Last active
November 23, 2023 07:20
-
-
Save kurokoleung/5b36b2013a54adadcce79967d3e4f056 to your computer and use it in GitHub Desktop.
CVE-2023-46945
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| [CVE ID] | |
| CVE-2023-46945 | |
| [PRODUCT] | |
| QD-20230821 | |
| [VERSION] | |
| from QD-20220208 to QD-20230821 | |
| [PROBLEM TYPE] | |
| Server-side request forgery | |
| [DESCRIPTION] | |
| QD provides OCR function. An attacker can control the URL of the verification code image, allowing the server to send external requests, leading to an SSRF vulnerability. This could allow an attacker to use this vulnerability to initiate requests for internal resources through the victim server. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment