Vulnerabilities > CVE-2018-9920 - Server-Side Request Forgery (SSRF) vulnerability in K2 Smartforms 4.6.11
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/147816/k2smartforms4611-ssrf.txt |
id | PACKETSTORM:147816 |
last seen | 2018-05-24 |
published | 2018-05-22 |
reporter | Foo Jong Meng |
source | https://packetstormsecurity.com/files/147816/K2-Smartforms-4.6.11-Server-Side-Request-Forgery.html |
title | K2 Smartforms 4.6.11 Server-Side Request Forgery |