Description
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
Remediation
References
Related Vulnerabilities
WordPress Plugin NextMove Lite-Thank You Page for WooCommerce Cross-Site Request Forgery (2.18.1)
Three.js Uncontrolled Resource Consumption Vulnerability (CVE-2020-28496)
WordPress Plugin Duplicator-WordPress Migration Remote Code Execution (1.2.40)
WordPress Plugin Import/Export Customizer Settings Cross-Site Request Forgery (1.0.3)
XWiki Missing Authentication for Critical Function Vulnerability (CVE-2022-24820)