2024-07-14 02:06:08 +00:00

91 lines
2.6 KiB
JSON

{
"id": "CVE-2023-48379",
"sourceIdentifier": "twcert@cert.org.tw",
"published": "2023-12-15T08:15:45.803",
"lastModified": "2023-12-21T15:50:53.093",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response."
},
{
"lang": "es",
"value": "Softnext Mail SQR Expert es una plataforma de gesti\u00f3n de correo electr\u00f3nico, tiene un filtrado inadecuado para un par\u00e1metro de URL espec\u00edfico dentro de una funci\u00f3n espec\u00edfica. Un atacante remoto no autenticado puede realizar un ataque Blind SSRF para descubrir la topolog\u00eda de la red interna bas\u00e1ndose en la respuesta de error de URL."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
},
{
"source": "twcert@cert.org.tw",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:softnext:mail_sqr_expert:*:*:*:*:*:*:*:*",
"versionEndIncluding": "230330",
"matchCriteriaId": "FDCE076E-BA94-4BFF-8FD9-4E08B4A6392F"
}
]
}
]
}
],
"references": [
{
"url": "https://www.twcert.org.tw/tw/cp-132-7597-fff54-1.html",
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
]
}
]
}