An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://git.tt-rss.org/fox/tt-rss/commit/c3d14e1fa54c7dade7b1b7955575e2991396d7ef | patch vendor advisory |
https://community.tt-rss.org/t/heads-up-several-vulnerabilities-fixed/3799 | vendor advisory |
http://packetstormsecurity.com/files/161606/TinyTinyRSS-Remote-Code-Execution.html | exploit vdb entry third party advisory |