Fireshare 是一个用于自托管媒体和链接共享的平台。在版本 1.6.16 之前,两个触发出站 HTTP 请求的 API 端点缺少 装饰器,导致未经身份验证的攻击者可以调用 或 ,使 Fireshare 服务器向攻击者提供的任意 URL(包括内网地址和云元数据服务)发起任意的 HTTP POST 请求。该漏洞无需任何凭证、会话 Cookie 或预先访问权限即可利用。该问题已在版本 1.6.16 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ShaneIsrael | fireshare | < 1.6.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet