go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Softnext Mail SQR Expert - Blind Server-Side Request Forgey (SSRF)

TVN ID TVN-202312008
CVE ID CVE-2023-48379
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products Softnext Mail SQR Expert before v230330
Description Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
Solution Update version to 230430
Credit Fi Liu(CHT Security)
Public Date 2023-12-15
Top