There was an error while loading. Please reload this page.
This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user.
The user portal form manager has been fixed to only instantiate classes derived from it.
No workaround.
Huge thanks to @worty-syn for reporting this.
If you have any questions or comments about this advisory: Email us at itop-security@combodo.com
Impact
This vulnerability can be used to create HTTP requests on behalf of the server, from a low privileged user.
Patches
The user portal form manager has been fixed to only instantiate classes derived from it.
Workarounds
No workaround.
References
Credits
Huge thanks to @worty-syn for reporting this.
For more information
If you have any questions or comments about this advisory:
Email us at itop-security@combodo.com