PT-2025-18714 · Sematell · Sematell Replyone
CVE-2024-48907
·
Publicado
2025-05-01
·
Atualizado
2025-05-03
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sematell ReplyOne version 7.4.3.0
Description
The issue allows Server-Side Request Forgery (SSRF) through the application server API. This means an attacker could potentially manipulate the server into making unauthorized requests.
Recommendations
For Sematell ReplyOne version 7.4.3.0, consider restricting access to the application server API to minimize the risk of exploitation. As a temporary workaround, review and limit the API's ability to make external requests until a patch is available.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sematell Replyone