CVE-2024-48346
EUVD-2024-4299730.10.2024, 21:15
xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| xtreme1-io | xtreme1 | 𝑥 ≤ 0.9.1 | ADP |