← Back

CVE-2024-48232

nvd nist
Published: Oct 25, 2024Modified: Jul 7, 2025

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.

Affected (1)

Products: Mipjz Project: Mipjz
1 product
Mipjz
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0.5

References (1)

Source: cve@mitre.org
ExploitIssue Tracking

Timeline

No history available yet.