Back

CVE-2017-12905

CRITICAL

Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.

Published: Sep 25, 2017 Modified: Jun 17, 2026
CWE-918

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
vebto pixie_-_image_editor 1.4
vebto pixie_-_image_editor 1.7

GitHub Security Advisory GHSA-v9qg-8jqw-q8xg

Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote...

References (2)

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 2.64%

Top 16% most likely to be exploited

Threat Score 40.8 / 100

Data Sources

NVD EPSS GitHub