What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Server Side Request Forgery.This issue affects Icegram Express Pro: from n/a through <= 5.9.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Server Side Request Forgery.This issue affects Icegram Express Pro: from n/a through <= 5.9.5.
Explanation of Vulnerability in Simple Terms
Icegram Express Pro versions up to 5.9.5 contain a server-side request forgery vulnerability that allows high-privilege users to make the site send requests to internal or external systems on their behalf. The attacker must have administrative access and the scope of impact extends beyond the vulnerable component. Low-level confidentiality and integrity impacts are possible.
What an attacker can do
Make the site send HTTP requests to internal systems or external servers under the site's identity.
Potential impact on your site
An admin account compromise could allow an attacker to probe internal infrastructure or interact with external APIs using your site.
Conditions required to exploit
Attacker must have high-level administrative privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities