CVE-2018-1000138
EUVD-2018-185623.03.2018, 21:29
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| scilico | i\,_librarian | 𝑥 ≤ 4.8 |
𝑥
= Vulnerable software versions
References