CVE-2018-9920
Published May 24, 2018Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.
Vendor/product archive
1 CVEs tagged to k2 / smartforms — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.