SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Apr 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sparkshop
Sparkshop sparkshop |
|
CPEs | cpe:2.3:a:sparkshop:sparkshop:*:*:*:*:*:*:*:* | |
Vendors & Products |
Sparkshop
Sparkshop sparkshop |
Wed, 30 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-918 | |
Metrics |
cvssV3_1
|
Mon, 28 Oct 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-30T16:59:38.111Z
Reserved: 2024-10-08T00:00:00
Link: CVE-2024-48107

Updated: 2024-10-30T16:54:21.402Z

Status : Analyzed
Published: 2024-10-28T21:15:09.453
Modified: 2025-04-18T01:19:44.297
Link: CVE-2024-48107

No data.