ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
2019-06-05T18:29:01.183
2024-11-21T04:51:10.110
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ikiwiki | ikiwiki | < 3.20170111.1 | Yes |
Application | ikiwiki | ikiwiki | < 3.20190226 | Yes |
Application | ikiwiki | ikiwiki | 3.20180105 | Yes |
Application | ikiwiki | ikiwiki | 3.20180228 | Yes |
Application | ikiwiki | ikiwiki | 3.20180311 | Yes |