elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usememos
Usememos memos |
|
| CPEs | cpe:2.3:a:usememos:memos:0.23.0:-:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Thu, 27 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-27T00:00:00.000Z
Updated: 2025-03-03T15:58:00.616Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2025-22952
Updated: 2025-03-03T15:57:57.290Z
Status : Analyzed
Published: 2025-02-27T20:16:04.983
Modified: 2025-07-10T22:52:03.177
Link: CVE-2025-22952
No data.