github.com
https://github.com/OpenXP-Research/CVE-2024-48360 CVE-2024-48360
HIGHNuclei
Qualitor <= v8.24 - Server-Side Request Forgery
Record summary
CVE-2024-48360 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
qualitorBrowse qualitor / qualitorDefault status: unknown | CVE List | 8.24 | affected |
Proofs of concept
1Repository PoCs
GitHubOpenXP-Research/CVE-2024-48360Repository PoCby OpenXP-ResearchStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHQualitor <= v8.24 - Server-Side Request ForgeryCVSS 7.5
Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
Impact
Unauthenticated attackers can force the server to make arbitrary requests via SSRF, potentially accessing internal services.
Remediation
Update Qualitor to a version later than 8.24 that patches the SSRF vulnerability.
WeaknessesCWE-918
Authorss4e-io
Template tagscvecve2024ssrfqualitorvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
FOFA: icon_hash="-1217039701"
https://github.com/OpenXP-Research/CVE-2024-48360 https://packetstormsecurity.com/files/182427/Qualitor-8.24-Server-Side-Request-Forgery.html https://nvd.nist.gov/vuln/detail/CVE-2024-48360
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-48360 qualitor.com.br
https://www.qualitor.com.br/official-security-advisory-cve-2024-48360 qualitor.com.br
https://www.qualitor.com.br/qualitor-8-20