CVE-2018-15657

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
05/02/2019
Last modified:
21/02/2019

Description

An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:42gears:suremdm:*:*:*:*:*:*:*:* 2018-11-27 (excluding)