What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Binsaifullah Beaf image-compare-block allows Server Side Request Forgery.This issue affects Beaf: from n/a through <= 1.6.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Binsaifullah Beaf image-compare-block allows Server Side Request Forgery.This issue affects Beaf: from n/a through <= 1.6.2.
Explanation of Vulnerability in Simple Terms
Beaf versions up to 1.6.2 contain a server-side request forgery vulnerability that allows high-privilege users to make the application send requests to internal or external systems on their behalf. The attacker must have administrative access and the scope of impact extends beyond the vulnerable component. Low-level data disclosure and modification are possible.
What an attacker can do
Make the site send HTTP requests to internal systems or external servers under the attacker's control.
Potential impact on your site
An admin account compromised or acting maliciously could probe your internal network or exfiltrate data via forced requests.
Conditions required to exploit
Attacker must have high-level administrative privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities