CVE-2023-48379
Softnext Mail SQR Expert - Blind Server-Side Request Forgey (SSRF)
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Softnext Mail SQR Expert es una plataforma de gestión de correo electrónico, tiene un filtrado inadecuado para un parámetro de URL específico dentro de una función específica. Un atacante remoto no autenticado puede realizar un ataque Blind SSRF para descubrir la topología de la red interna basándose en la respuesta de error de URL.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-11-16 CVE Reserved
- 2023-12-15 CVE Published
- 2023-12-16 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
- CAPEC-664: Server Side Request Forgery
References (1)
URL | Tag | Source |
---|---|---|
https://www.twcert.org.tw/tw/cp-132-7597-fff54-1.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Softnext Search vendor "Softnext" | Mail Sqr Expert Search vendor "Softnext" for product "Mail Sqr Expert" | <= 230330 Search vendor "Softnext" for product "Mail Sqr Expert" and version " <= 230330" | - |
Affected
|