Security Advisory

CVE-2018-9920

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-05-24 13:00:00
Last updated 2024-08-05 07:24:56
Assigner mitre
State PUBLISHED

Description

Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.