A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
References
Link Resource
https://hackerone.com/reports/243865 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-07-09T20:00:00

Updated: 2018-07-09T20:57:01

Reserved: 2018-07-09T00:00:00


Link: CVE-2018-13790

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-09T20:29:00.957

Modified: 2021-07-15T20:42:25.937


Link: CVE-2018-13790

JSON object: View

cve-icon Redhat Information

No data.

CWE