Record summary

CVE-2021-46107 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHLigeo Archives Ligeo Basics - Server Side Request ForgeryCVSS 7.5

Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.

Impact

The impact of this vulnerability is significant as it can result in unauthorized access to sensitive data or systems.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the Server Side Request Forgery vulnerability.

WeaknessesCWE-918
Authorsritikchaddha
Template tagscve2021cveligeossrflfrligeo-archivesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:ligeo-archives:ligeo_basics:02_01-2022:*:*:*:*:*:*:*
Shodan: title:"Ligeo"
Shodan: http.title:"ligeo"
FOFA: title="Ligeo"
FOFA: title="ligeo"
Google: intitle:"ligeo"

Source: ProjectDiscovery

References

3