A limited SSRF vulnerability exists on Western Digital My Cloud devices that could allow an malicious user to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
westerndigital my_cloud_os |