VuFind Server-Side Request Forgery (SSRF) vulnerability
Critical severity
GitHub Reviewed
Published
May 22, 2024
to the GitHub Advisory Database
•
Updated Nov 12, 2024
Description
Published by the National Vulnerability Database
May 22, 2024
Published to the GitHub Advisory Database
May 22, 2024
Reviewed
May 23, 2024
Last updated
Nov 12, 2024
A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open Library Foundation VuFind 2.4 through 9.1 before 9.1.1 allows remote attackers to access internal HTTP servers and perform Cross-Site Scripting (XSS) attacks by proxying arbitrary URLs via the proxy GET parameter.
References