Known CVE
Memos 0.13.2 - Server-Side Request Forgery
SSRF vulnerabilities exist in the memos API service `/o/get/httpmeta` that allow unauthenticated and authenticated users to enumerate and read from the internal network. In addition, one SSRF vulnerability leads to a reflected XSS vulnerability, which may allow an attacker complete control over the administrator account.
CVE-2024-29028
Medium2024CVSS 5.3CWE-918
cve2024 · ssrf · memos · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website