Vulnerabilities > CVE-2023-39854 - Server-Side Request Forgery (SSRF) vulnerability in ATX Ucrypt 3.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |