Illia Cloud illia-Builder Server-Side Request Forgery Vulnerability
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Illia Cloud illia-Builder versions prior to 4.8.5. This vulnerability allows authenticated users to send arbitrary requests to internal services via the API. Exploitation of this vulnerability could enable an attacker to enumerate open ports based on response discrepancies and interact with internal services.
Impact
Exploitation of this vulnerability could lead to unauthorized access to internal services, allowing for potential data exfiltration or manipulation. Additionally, the vulnerability could be used to perform port scanning activities, identifying open ports and services running on the internal network.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
