Description
Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.
References (1)
Core 1
Core References
Scores
CVSS v3
6.4
EPSS
0.0025
EPSS Percentile
16.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (2)
Bernhard Kux/JSON Content Importer
< 1.5.6
json-content-importer/json_content_importer
< 1.6.0
Published
Jul 22, 2024
Tracked Since
Feb 18, 2026