CVE-2023-7037
Last modified
CVE-2023-7037 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was found in automad up to 1.10.9. It has been declared as critical. EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileController.php. The manipulation of the argument importUrl leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-248686 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Automad | Automad | <= 1.10.9 |
References
- https://github.com/screetsec/VDD/tree/main/Automad%20CMS/Authenticated%20Blind%20SSRFExploit, Third Party Advisory
- https://vuldb.com/?ctiid.248686Permissions Required, Third Party Advisory
- https://vuldb.com/?id.248686Permissions Required, Third Party Advisory
- https://github.com/screetsec/VDD/tree/main/Automad%20CMS/Authenticated%20Blind%20SSRFExploit, Third Party Advisory
- https://vuldb.com/?ctiid.248686Permissions Required, Third Party Advisory
- https://vuldb.com/?id.248686Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-7037?
How severe is CVE-2023-7037?
How do I fix CVE-2023-7037?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-7030The Collapse-O-Matic plugin for WordPress is vulnerable to S…6.4
- CVE-2023-7031Insecure Direct Object Reference vulnerabilities were discov…4.3
- CVE-2023-7032 A CWE-502: Deserialization of untrusted data vulnerability …7.8
- CVE-2023-7033Insufficient Resource Pool vulnerability in Ethernet functio…5.3
- CVE-2023-7035A vulnerability was found in automad up to 1.10.9 and classi…5.4
- CVE-2023-7036A vulnerability was found in automad up to 1.10.9. It has be…5.4
- CVE-2023-7038A vulnerability was found in automad up to 1.10.9. It has be…6.5
- CVE-2023-7039A vulnerability classified as critical has been found in Byz…9.8
- CVE-2023-7040A vulnerability classified as problematic was found in codel…6.5
- CVE-2023-7041A vulnerability, which was classified as critical, has been …5.4
- CVE-2023-7042A null pointer dereference vulnerability was found in ath10k…5.5
- CVE-2023-7043Unquoted service path in ESET products allows to drop a pr…5.5
Are you affected by CVE-2023-7037?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
