CVE-2024-55089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
18/12/2024
Last modified:
20/02/2026

Description

Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rhymix:rhymix:2.1.19:*:*:*:*:*:*:*