Vulnerabilities > CVE-2020-21122 - Server-Side Request Forgery (SSRF) vulnerability in Ureport Project Ureport 2.2.9

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ureport-project
CWE-918

Summary

UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

Vulnerable Configurations

Part Description Count
Application
Ureport_Project
1

Common Weakness Enumeration (CWE)