Webstudio 0.296.0 及更早版本中的 /cgi/image、/cgi/video 和 /cgi/asset 代理路由存在未认证的服务器端请求伪造漏洞,前提是 环境变量未设置。攻击者可以向这些端点提供任意 URL,从而读取云实例元数据、访问内部服务,并对实例基础设施进行网络侦察。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| webstudio-is | webstudio | ≤ 0.296.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| webstudio-is | webstudio | 0 ~ 0.296.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet