CRITICAL 9.1
GHSA-9mmg-q95p-gp67
Project Firefly III has incorrect access control in the webhook management component
Details
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / grumpydictator/firefly-iii
Introduced in:
0 No fixed version published yet for grumpydictator/firefly-iii (composer). Pin to a known-safe version or switch to an alternative.