Skip to content

Instantly share code, notes, and snippets.

@kurokoleung
Last active November 23, 2023 07:20
Show Gist options
  • Select an option

  • Save kurokoleung/5b36b2013a54adadcce79967d3e4f056 to your computer and use it in GitHub Desktop.

Select an option

Save kurokoleung/5b36b2013a54adadcce79967d3e4f056 to your computer and use it in GitHub Desktop.
CVE-2023-46945
[CVE ID]
CVE-2023-46945
[PRODUCT]
QD-20230821
[VERSION]
from QD-20220208 to QD-20230821
[PROBLEM TYPE]
Server-side request forgery
[DESCRIPTION]
QD provides OCR function. An attacker can control the URL of the verification code image, allowing the server to send external requests, leading to an SSRF vulnerability. This could allow an attacker to use this vulnerability to initiate requests for internal resources through the victim server.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment