CVE-2017-14323: Onethink
Critical severity, CVSS 9.8. EPSS: 4.3% chance of exploitation in the next 30 days.
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.
Affected products
- Onethink Onethink: version 1.0 only; version 1.1 only
Published 2018-04-10. Last modified 2026-06-17.