LyLme spage v1.9.5 is vulnerable to server-side request forgery (SSRF) via the url parameter in apply/index.php. An attacker can force the server to make arbitrary requests, potentially accessing internal resources.
id: CVE-2024-36675
info:
name: LyLme spage v1.9.5 - Server-Side Request Forgery
author: ritikch
...