Security Advisory

CVE-2024-48346

6.1
MEDIUM

Vulnerability Description

xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.
Published Date October 30, 2024
Official Source NIST NVD Advisory