CVE-2024-36675
lylme lylme_spage Server-Side Request Forgery (SSRF)
Record summary
CVE-2024-36675 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 1, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
lylme_spageBrowse lylme / lylme_spageDefault status: unknown | CVE List, VulnCheck | 1.9.5 | affected |
Nuclei templates
1ProjectDiscoveryHIGHLyLme spage v1.9.5 - Server-Side Request ForgeryCVSS 9.1
LyLme spage v1.9.5 is vulnerable to server-side request forgery (SSRF) via the url parameter in apply/index.php. An attacker can force the server to make arbitrary requests, potentially accessing internal resources.
Impact
Unauthenticated attackers can force the server to make arbitrary requests via the url parameter, potentially accessing internal resources.
Remediation
Update LyLme spage to a version later than v1.9.5 that patches the SSRF vulnerability.
Source: ProjectDiscovery