VDB
CRITICAL 9.1

GHSA-9mmg-q95p-gp67

Project Firefly III has incorrect access control in the webhook management component

Details

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / grumpydictator/firefly-iii
Introduced in: 0

No fixed version published yet for grumpydictator/firefly-iii (composer). Pin to a known-safe version or switch to an alternative.

References