Vulnerabilities > CVE-2022-24980 - Server-Side Request Forgery (SSRF) vulnerability in Kitodo Kitodo.Presentation 3.1.2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
kitodo
CWE-918

Summary

An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to.

Vulnerable Configurations

Part Description Count
Application
Kitodo
2

Common Weakness Enumeration (CWE)