Record summary

CVE-2024-36675 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 1, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheck1.9.5affected

Nuclei templates

1
ProjectDiscoveryHIGHLyLme spage v1.9.5 - Server-Side Request ForgeryCVSS 9.1

LyLme spage v1.9.5 is vulnerable to server-side request forgery (SSRF) via the url parameter in apply/index.php. An attacker can force the server to make arbitrary requests, potentially accessing internal resources.

Impact

Unauthenticated attackers can force the server to make arbitrary requests via the url parameter, potentially accessing internal resources.

Remediation

Update LyLme spage to a version later than v1.9.5 that patches the SSRF vulnerability.

WeaknessesCWE-918
Authorsritikchaddha
Template tagscvecve2024ssrflylmespageoastoobvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CPE: cpe:2.3:a:lylme:lylme_spage:1.9.5:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-282504889
FOFA: title="LyLme Spage"

Source: ProjectDiscovery

References

2