Looking for the vulnerability index of Invicti's legacy products?
GeoServer WMS SSRF (CVE-2023-43795) - Vulnerability Database

GeoServer WMS SSRF (CVE-2023-43795)

Description

GeoServer WMS allows an unauthenticated attacker to send arbitrary requests to perform lookups on the internal network which is otherwise not accessible externally. An attacker may use this feature to perform SSRF (server-side request forgery) attacks on the server.

Remediation

Upgrade to the latest version of GeoServer

Related Vulnerabilities