Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System Server-Side Request Forgery Vulnerability
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System version 3.0. The issue arises in the file protocol handler component, specifically within an unknown functionality of the file 'imageProxy.do'. The vulnerability is triggered by manipulating the 'xyImgUrl' argument, allowing remote attackers to send unauthorized requests from the server.
Impact
Exploitation of this vulnerability allows for server-side request forgery, where an attacker can make the server send requests to internal or external resources, potentially leading to further exploitation or information disclosure.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
