CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-39854
Severity
MEDIUM
CVSS
6.5
EPSS
0.43%
Original NVD Description
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.
Related CVEs
Other vulnerabilities affecting the same vendor(s)