Vulnerabilities (CVE)

Filtered by vendor Nbnbk Project Subscribe
Filtered by product Nbnbk
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31386 1 Nbnbk Project 1 Nbnbk 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.