What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/a through 1.18.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/a through 1.18.11.
Explanation of Vulnerability in Simple Terms
HTTP Headers is a library that can be abused to make the site send requests to internal or external systems on an attacker's behalf. An authenticated administrator with high privileges can craft a request that causes the library to fetch a URL they specify, potentially accessing internal services or exfiltrating data. The impact is limited to low-level information disclosure and modification.
What an attacker can do
Make the site send HTTP requests to internal or external systems the attacker specifies.
Potential impact on your site
A compromised admin account could be used to probe internal networks or access restricted services via your site.
Conditions required to exploit
Attacker must have high-level administrator privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities