Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-9920

Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.4
Products affected by CVE-2018-9920
  • K2 » Smartforms » Version: 4.6.11
    cpe:2.3:a:k2:smartforms:4.6.11


Contact Us

Shodan ® - All rights reserved