EIQ-2023-0002#
ID |
EIQ-2023-0002 |
---|---|
Product |
EclecticIQ Intelligence Center |
CVE |
N/A |
Description |
Bypassing report content sanitization using API calls allows possible SSRF and directory traversal |
Date |
28 February 2023 |
Severity |
3 - HIGH |
CVSSv3 score |
7.7 |
Status |
✅ 3.0.0 |
Assessment |
The Intelligence Center (IC) is vulnerable to server-side request forgery (SSRF) and directory traversal attacks when a report entity is created on the IC containing an anchor tag (
When this report entity is exported as a PDF, the IC creates the PDF and embeds the content of the resource specified in that anchor tag. Whomever subsequently opens the resulting PDF can click on the link created by the anchor tag and open the embedded resource. To replicate:
|
Mitigation |
- |
Affected versions |
2.14.x and earlier. |
Notes |
N/A |