Description
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server.
Remediation
References
https://www.youtube.com/watch?v=JE1Kcq3iJpc
Related Vulnerabilities
CVE-2021-32730 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2020-7719 Vulnerability in npm package locutus
CVE-2021-23574 Vulnerability in npm package js-data
CVE-2016-0712 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed-portal
CVE-2022-37423 Vulnerability in maven package org.neo4j.procedure:apoc