CVE-2024-48346
30.10.2024, 21:15
xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.
Awaiting analysis
This vulnerability is currently awaiting analysis.