Description
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Ping Optimizer Cross-Site Request Forgery (2.35.1.2.3)
WordPress Plugin External Links-nofollow, noopener & new window Cross-Site Scripting (2.55)
WordPress Plugin Easy Registration Forms Cross-Site Scripting (1.8.3)
Oracle Application Server Other Vulnerability (CVE-2002-0559)