该段文字描述了 Lara Dashboard 软件中的一个安全漏洞。以下是其准确、专业的中文翻译: Lara Dashboard 1.3.1 及更早版本存在服务器端请求伪造(SSRF)漏洞,位于 POST /api/admin/builder/markdown/fetch 端点。该漏洞允许任何经过身份验证的用户获取任意 URL 并读取响应体。攻击者可通过提供恶意 URL 来读取内部 HTTP 服务和云元数据(包括 IAM 凭据),且该端点缺乏对主机的验证或重定向限制。 关键术语说明: Server-side req
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| laradashboard | laradashboard | 0.9.2 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet