CVE-2018-10220: Mushmush Glastopf

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote File Inclusion emulation

Affected products

Published 2018-04-19. Last modified 2026-06-17.