Record summary

CVE-2024-48360 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 1, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List8.24affected

Proofs of concept

1

Repository PoCs

GitHubOpenXP-Research/CVE-2024-48360Repository PoCby OpenXP-ResearchStars: 0Not analyzed1 file

913 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHQualitor <= v8.24 - Server-Side Request ForgeryCVSS 7.5

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

Impact

Unauthenticated attackers can force the server to make arbitrary requests via SSRF, potentially accessing internal services.

Remediation

Update Qualitor to a version later than 8.24 that patches the SSRF vulnerability.

WeaknessesCWE-918
Authorss4e-io
Template tagscvecve2024ssrfqualitorvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
FOFA: icon_hash="-1217039701"

Source: ProjectDiscovery

References

4