CVE-2023-4624
published 2023-08-30CVE-2023-4624: Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
PriorityP48low2.4CVSS 3.1
AVNACLPRHUIRSUCLINAN
EPSS
0.53%
40.9th percentile
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bookstackapp | bookstack | < 23.08 | 23.08 |
| bookstackapp | bookstackapp_bookstack | >= unspecified < v23.08 | v23.08 |
CVSS provenance
nvdv3.12.4LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
nvdv3.02.4LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/bookstackapp/bookstack/commit/c324ad928dbdd54ce5b09eb0dabe60ef9de1ea38https://huntr.dev/bounties/9ce5cef6-e546-44e7-addf-a2726fa4e60chttps://github.com/bookstackapp/bookstack/commit/c324ad928dbdd54ce5b09eb0dabe60ef9de1ea38https://huntr.dev/bounties/9ce5cef6-e546-44e7-addf-a2726fa4e60c
2023-08-30
Published