Description LyLme spagev1.9.5容易通过apply/index.php中的url参数受到服务器端请求伪造(SSRF)的攻击。攻击者可以迫使服务器发出任意请求,从而可能访问内部资源。
References https://nvd.nist.gov/vuln/detail/CVE-2024-36675 https://github.com/LyLme/lylme_spage/issues/92 https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/cves/2024/CVE-2024-36675.yaml https://cve.imfht.com/detail/CVE-2024-36675 https://www.tutusec.com/2313.html https://ddpoc.com/DVB-2025-9683.html https://intel.enki-guard.com/vulnerability/CVE-2024-36675-lylme-spage-ssrf-via-get-head https://opencve.ameos.net/cve/?vendor=lylme&product=lylme_spage https://www.tenable.com/cve/CVE-2024-36675 https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-36675
Related VulnerabilitiesPoCCVE-2021-33807: Cartadis Gespage 8.2.1 - Directory TraversalPoCCVE-2024-34982: LyLme-Spage - Arbitary File UploadPoCCVE-2024-36675: LyLme spage v1.9.5 - Server-Side Request ForgeryPoCimpresspages-installer: ImpressPages Installerlylme_spage 存在任意文件上传漏洞(CVE-2024-34982)LyLme Spage /include/file.php 任意文件上传漏洞lylme_spage CVE-2023-45951 SQL注入漏洞LyLme Spage index SQL注入漏洞Cartadis Gespage 8.2.1 存在目录遍历漏洞(CVE-2021-33807)ImpressPages CMS未明远程代码执行漏洞