6.5
CVSSv3

CVE-2018-9920

Published: 24/05/2018 Updated: 27/02/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an */Identity/STS/Forms/Scripts URL.

Vulnerable Product Search on Vulmon Subscribe to Product

k2 smartforms 4.6.11

Exploits

K2 Smartforms version 4611 suffers from a server-side request forgery vulnerability ...