Description
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
Remediation
References
https://github.com/fex-team/kityminder/issues/345
Related Vulnerabilities
CVE-2020-28460 Vulnerability in npm package multi-ini
CVE-2023-46998 Vulnerability in maven package org.webjars.bowergithub.makeusabrew:bootbox
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap
CVE-2020-14968 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2023-31718 Vulnerability in npm package @frangoteam/fuxa