CVE-2023-3744: Server-Side Request Forgery in SLiMS
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrapeimage.php" file in the imageURL parameter.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-3744?
CVE-2023-3744 is a Server-Side Request Forgery vulnerability in SLims version 9.6.0.
How does CVE-2023-3744 impact SLims version 9.6.0?
CVE-2023-3744 allows an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.
Is CVE-2023-3744 a critical vulnerability?
Yes, CVE-2023-3744 has a severity value of 8.8, indicating a critical vulnerability.
How can I fix CVE-2023-3744 in SLims version 9.6.0?
To fix CVE-2023-3744, update to a version of SLims that is not affected by this vulnerability.
Where can I find more information about CVE-2023-3744?
You can find more information about CVE-2023-3744 at the following reference: https://www.incibe.es/en/incibe-cert/notices/aviso/server-side-request-forgery-slims