QD Server-Side Request Forgery Vulnerability
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in QD version QD-20230821, affecting all versions from QD-20220208 to QD-20230821. This vulnerability arises because the application allows users to control the URL of the verification code image for its optical character recognition (OCR) function. An attacker could exploit this feature to have the server make external requests, potentially accessing internal resources through the victim's server.
Impact
Exploitation of this vulnerability could allow an attacker to use the affected server as a proxy to access internal resources, which could lead to further attacks or information disclosure.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
