VULNERABILITY INTELLIGENCE

CVE-2017-7553

CVSS score6.3 MEDIUM
EPSS probability0.70%
CISA KEVNot currently listed
Published2017-09-29
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Description

The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.

Weakness classification

  • CWE-918: Server-Side Request Forgery (SSRF)

Primary references