Vulnerabilities > CVE-2018-9920 - Server-Side Request Forgery (SSRF) vulnerability in K2 Smartforms 4.6.11
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/147816/k2smartforms4611-ssrf.txt |
id | PACKETSTORM:147816 |
last seen | 2018-05-24 |
published | 2018-05-22 |
reporter | Foo Jong Meng |
source | https://packetstormsecurity.com/files/147816/K2-Smartforms-4.6.11-Server-Side-Request-Forgery.html |
title | K2 Smartforms 4.6.11 Server-Side Request Forgery |