Description
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
Remediation
References
https://github.com/fex-team/kityminder/issues/345
Related Vulnerabilities
CVE-2020-11973 Vulnerability in maven package org.apache.camel:camel-netty
CVE-2017-16158 Vulnerability in npm package dcserver
CVE-2022-39944 Vulnerability in maven package org.apache.linkis:linkis-engineplugin-jdbc
CVE-2021-21363 Vulnerability in maven package io.swagger:swagger-generator
CVE-2023-33831 Vulnerability in npm package @frangoteam/fuxa