CVE-2023-39854

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
09/10/2023
Last modified:
01/02/2024

Description

The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atx:ucrypt:*:*:*:*:*:*:*:* 3.5 (including)


References to Advisories, Solutions, and Tools