CVE-2024-6424

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
01/07/2024
Last modified:
22/10/2025

Description

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mesbook:mesbook:20221021.03:*:*:*:*:*:*:*