Description
It was determined that the web application performs a server-side rendering/processing of a user supplied data in insecure way. An unauthenticated attacker could use this vulnerability to send requests to restricted services. Also, in certain cases, it may be possible to read arbitrary local files of the system.
Remediation
Sanitize user's data
References
Related Vulnerabilities
ColdFusion WDDX Deserialization RCE (CVE-2023-29300/CVE-2023-38203/CVE-2023-38204)
OpenCms Chemistry XML External Entity (XXE) vulnerability (CVE-2023-42344)
WordPress Plugin All in One Social Lite Server-Side Request Forgery (1.0)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17670)