CVE-2021-28060

Publication date

2021-04-14 16:11:18

Family

mitre

State

PUBLISHED

Description

A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.