A vulnerability was found in wangl1989 mysiteforme 1.0. It has been rated as critical. This issue affects the function doContent of the file src/main/java/com/mysiteform/admin/controller/system/FileController. The manipulation of the argument content leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Link | Tags |
---|---|
https://vuldb.com/?id.290213 | third party advisory vdb entry technical description |
https://vuldb.com/?ctiid.290213 | signature vdb entry permissions required |
https://vuldb.com/?submit.468513 | third party advisory vdb entry |
https://github.com/wangl1989/mysiteforme/issues/56 | issue tracking exploit |
https://github.com/wangl1989/mysiteforme/issues/56#issue-2757876365 | issue tracking exploit |