CVE-2023-31456
Last modified
CVE-2023-31456 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitrary requests to internal and external resources by an authenticated user.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitrary requests to internal and external resources by an authenticated user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-31456?
How severe is CVE-2023-31456?
How do I fix CVE-2023-31456?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3145A vulnerability, which was classified as critical, has been …8.8
- CVE-2023-31450A path traversal vulnerability was identified in the SQL v2 …4.7
- CVE-2023-31452A cross-site request forgery (CSRF) token bypass was identif…8.8
- CVE-2023-31453Incorrect Permission Assignment for Critical Resource Vulner…7.5
- CVE-2023-31454Incorrect Permission Assignment for Critical Resource Vulner…7.5
- CVE-2023-31455Pexip Infinity before 31.2 has Improper Input Validation for…7.5
- CVE-2023-31457A vulnerability in the Headquarters server component of Mite…9.8
- CVE-2023-31458A vulnerability in the Edge Gateway component of Mitel MiVoi…9.8
- CVE-2023-31459A vulnerability in the Connect Mobility Router component of …8.8
- CVE-2023-3146A vulnerability, which was classified as critical, was found…8.8
- CVE-2023-31460A vulnerability in the Connect Mobility Router component of …7.2
- CVE-2023-31461Attackers can exploit an open API listener on SteelSeries GG…7.5
Are you affected by CVE-2023-31456?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
