A Server-Side Request Forgery (SSRF) in the component...
Moderate severity
Unreviewed
Published
Jul 18, 2025
to the GitHub Advisory Database
•
Updated Jul 18, 2025
Description
Published by the National Vulnerability Database
Jul 18, 2025
Published to the GitHub Advisory Database
Jul 18, 2025
Last updated
Jul 18, 2025
A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure.
References