CVE-2024-35451: SSRF
Published Nov 29, 2024
·Updated
LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
Affected Software
2 affected components
linkstack linkstack>=2.7.9<4.7.7
linkstack linkstack>=2.7.9<=4.7.7
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35451?
CVE-2024-35451 is classified as a critical vulnerability due to its potential to lead to remote code execution.
2
What systems are affected by CVE-2024-35451?
CVE-2024-35451 affects LinkStack versions from 2.7.9 to 4.7.7.
3
How do I fix CVE-2024-35451?
To fix CVE-2024-35451, upgrade to a version of LinkStack later than 4.7.7.
4
What type of vulnerability is CVE-2024-35451?
CVE-2024-35451 is a server-side request forgery (SSRF) vulnerability.
5
What is the impact of exploitation of CVE-2024-35451?
Exploitation of CVE-2024-35451 could allow an attacker to perform unauthorized actions on the server, potentially leading to data breaches.