NA

CVE-2023-45152

Published: 17/10/2023 Updated: 30/10/2023
CVSS v3 Base Score: 2.3 | Impact Score: 1.4 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

engelsystem engelsystem

Github Repositories

About me πŸ‘‹ πŸ”Ž Job title: Application Security Engineer πŸŒ‡ Current location: Moscow, Russia πŸ’₯ Certificates: OSCP (November 2021) πŸ’’ CVEs: CVE-2023-45659 CVE-2023-45152 CVE-2023-5838 CVE-2023-5840 πŸͺ Open for collaboration