What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy genemy allows Server Side Request Forgery.This issue affects Genemy: from n/a through <= 1.6.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy genemy allows Server Side Request Forgery.This issue affects Genemy: from n/a through <= 1.6.6.
Explanation of Vulnerability in Simple Terms
Genemy versions up to 1.6.6 contain a server-side request forgery vulnerability that allows an authenticated attacker to make the site send HTTP requests to internal or external systems on their behalf. The attacker needs low-level authentication and the scope extends beyond the vulnerable component. This could expose internal services or be used to interact with external APIs.
What an attacker can do
Make the site send HTTP requests to internal or external systems on the attacker's behalf.
Potential impact on your site
Authenticated users can probe internal network services or interact with external APIs, potentially exposing sensitive data or causing unintended actions.
Conditions required to exploit
Attacker must have low-level authentication access to the site.
Key dates
External resources
Related vulnerabilities