crmeb_java v1.3.4 was discovered to contain a Server-Side...
Moderate severity
Unreviewed
Published
May 6, 2024
to the GitHub Advisory Database
•
Updated Dec 6, 2024
Description
Published by the National Vulnerability Database
May 6, 2024
Published to the GitHub Advisory Database
May 6, 2024
Last updated
Dec 6, 2024
crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.
References