Vulnerabilities > CVE-2022-24862 - Server-Side Request Forgery (SSRF) vulnerability in Databasir Project Databasir 1.0.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Request Forgery vulnerability. During the download verification process of a JDBC driver the corresponding JDBC driver download address will be downloaded first, but this address will return a response page with complete error information when accessing a non-existent URL. Attackers can take advantage of this feature for SSRF.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |