Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EverShop 安全漏洞
Vulnerability Description
EverShop是EverShop开源的一个 NodeJS 电商平台。 EverShop 2.1.0及之前版本存在安全漏洞,该漏洞源于对src查询参数验证不足,可能导致服务端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A