CVE-2021-33213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
14/07/2021
Last modified:
16/07/2021

Description

An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:element-it:http_commander:5.3.3:*:*:*:*:*:*:*