elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://elest.io/open-source/memos | Product |
https://github.com/usememos/memos | Product |
https://github.com/usememos/memos/issues/4413 | Exploit Issue Tracking Vendor Advisory |
https://github.com/usememos/memos/issues/4413 | Exploit Issue Tracking Vendor Advisory |
https://github.com/usememos/memos/pull/4428 | Issue Tracking Patch |
Configurations
History
10 Jul 2025, 22:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Usememos
Usememos memos |
|
CPE | cpe:2.3:a:usememos:memos:0.23.0:-:*:*:*:*:*:* | |
References | () https://github.com/usememos/memos/issues/4413 - Exploit, Issue Tracking, Vendor Advisory | |
References | () https://github.com/usememos/memos - Product | |
References | () https://github.com/usememos/memos/pull/4428 - Issue Tracking, Patch | |
References | () https://elest.io/open-source/memos - Product |
27 Feb 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 20:16
Updated : 2025-07-10 22:52
NVD link : CVE-2025-22952
Mitre link : CVE-2025-22952
JSON object : View
Products Affected
usememos
- memos
CWE
No CWE.