PT-2023-29440 · Unknown · Engelsystem

·

CVE-2023-45152

·

Published

2023-10-16

·

Updated

2023-10-30

CVSS v3.1

2.0

Low

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Engelsystem versions prior to the version containing commit ee7d30b33
Description Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment.
Recommendations For versions prior to the version containing commit ee7d30b33, ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-45152
GHSA-JJ9G-75WF-6PPF

Affected Products

Engelsystem