Book Stack v23.10.2 - LFR via Blind SSRF
7,1
High
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Book Stack v23.10.2 - LFR via Blind SSRF
Code name
State
Public
Release date
20 nov 2023
Affected product
Book Stack
Affected version(s)
Version 23.10.2
Vulnerability name
Server-side request forgery (SSRF)
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS v3.1 base score
7.1
Exploit available
No
CVE ID(s)
Description
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in Book Stack that, under certain conditions, could allow an attacker to obtain local files from the server. The attacker must have writer permissions.
POC
Evidence of exploitation
Our security policy
We have reserved the ID CVE-2023-6199 to refer to this issue from now on. Disclosure policy
System Information
Version: Book Stack 23.10.2
Operating System: MacOS
Mitigation
An updated version of BookStack is available at the vendor page.
References
Vendor page https://github.com/BookStackApp/BookStack/
BookStack release https://www.bookstackapp.com/blog/bookstack-release-v23-10-3/
Timeline
IA generativa
17 nov 2023
Vendor Confirmed Vuln.
19 nov 2023
Vulnerability patched
20 nov 2023
Vendor contacted
18 nov 2023
Vendor replied
19 nov 2023
Public disclosure
20 nov 2023