2018-12-28 17:29:04 2019-03-12 13:16:18

JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.

Vector

NETWORK

Complexity

LOW

Authentication

SINGLE_INSTANCE

Confidentiality

PARTIAL

Integrity

NONE

Availability

NONE