在 projeto-siga siga 的 11.1.1 及更早版本中发现了一个安全弱点。该问题影响位于 文件中的 函数,该函数属于 HTML-to-PDF Endpoint 组件。对参数 的操纵可能导致 服务端请求伪造(SSRF, Server-Side Request Forgery)。该攻击可以远程发起。该漏洞的利用方式已经公开,可被用于实际攻击。项目方通过问题报告早期得知了此问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| projeto-siga | siga | 11.1.0 |
cpe:2.3:a:projeto-siga:siga:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet