Skip to content

Known CVE

Memos 0.13.2 - Server-Side Request Forgery

SSRF vulnerabilities exist in the memos API service `/o/get/httpmeta` that allow unauthenticated and authenticated users to enumerate and read from the internal network. In addition, one SSRF vulnerability leads to a reflected XSS vulnerability, which may allow an attacker complete control over the administrator account.

CVE-2024-29028

Medium2024CVSS 5.3CWE-918

cve2024 · ssrf · memos · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website