Vulnerabilities > CVE-2017-20106 - Server-Side Request Forgery (SSRF) vulnerability in Khoros Lithium Forum 2017

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
local
low complexity
khoros
CWE-918

Summary

A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

Vulnerable Configurations

Part Description Count
Application
Khoros
1

Common Weakness Enumeration (CWE)