Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-13650

An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal component, the request is blind, but through the error message it's possible to determine whether the request targeted a open service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.0%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-13650
  • Digdash » Digdash » Version: 2018r2
    cpe:2.3:a:digdash:digdash:2018r2
  • Digdash » Digdash » Version: 2019r1
    cpe:2.3:a:digdash:digdash:2019r1
  • Digdash » Digdash » Version: 2019r2
    cpe:2.3:a:digdash:digdash:2019r2


Contact Us

Shodan ® - All rights reserved