CVE-2017-20106

MEDIUM

Lithium Forum 2017 Q1 - Server-Side Request Forgery via Compose Message Handler

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

References (2)

Core 2
Core References
Exploit, Mitigation, Third Party Advisory x_refsource_misc
https://www.vulnerability-lab.com/get_content.php?id=2030
Permissions Required, Third Party Advisory x_refsource_misc
https://vuldb.com/?id.97265

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 24.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
khoros/lithium_forum 2017 q1
Published Jun 28, 2022
Tracked Since Feb 18, 2026