Blind Server-Side Request Forgery (SSRF) vulnerability in...
High severity
Unreviewed
Published
Jan 10, 2024
to the GitHub Advisory Database
•
Updated Jan 26, 2024
Description
Published by the National Vulnerability Database
Jan 10, 2024
Published to the GitHub Advisory Database
Jan 10, 2024
Last updated
Jan 26, 2024
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code.
References