CVE-2023-3744
Last modified
CVE-2023-3744 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Slims | Senayan Library Management System | 9.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3744?
How severe is CVE-2023-3744?
How do I fix CVE-2023-3744?
Are you affected by CVE-2023-3744?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
