CVE-2022-36551
MEDIUMHeartex - Label Studio Community Edition <1.5.0 - SSRF
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-36551. PoCs published by Ryan Smith.
AI-analyzed exploit summary This Python script exploits an authenticated SSRF vulnerability in Label Studio <=1.5.0 by creating a project, importing a file via a crafted URL (e.g., file:///etc/passwd), and retrieving its contents. It supports self-registration if enabled.
Description
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.
Exploits (1)
This Python script exploits an authenticated SSRF vulnerability in Label Studio <=1.5.0 by creating a project, importing a file via a crafted URL (e.g., file:///etc/passwd), and retrieving its contents. It supports self-registration if enabled.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N