S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-46107 Scanner

CVE-2021-46107 scanner - Server Side Request Forgery vulnerability in Ligeo Archives Ligeo Basics

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-46107
7.5
CVSS

Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Ligeo Archives Ligeo Basics is a comprehensive archival management software designed for organizing, preserving, and accessing digital archives. This platform is utilized by libraries, museums, and archival institutions to manage their collections digitally. It offers features for cataloging, search, and retrieval of documents, making it an essential tool for historians, researchers, and archivists. The software aims to simplify the archival process while ensuring the accessibility and preservation of historical documents and artifacts.

The vulnerability is present in the document download functionality, where an attacker can manipulate the file parameter to request internal files or interact with internal services. Specifically, the software does not adequately validate or sanitize the input for the file parameter in the download request, allowing for external URLs or file paths to be specified. This can lead to the disclosure of sensitive system files, such as /etc/passwd, or interaction with internal network services through crafted URLs.

Exploitation of this SSRF vulnerability can lead to significant security breaches, including unauthorized access to sensitive documents, data leaks, and potential internal network reconnaissance. Attackers could exploit this flaw to gain insights into internal systems, extract confidential information, or even perform actions on behalf of the server, posing a critical risk to the security and privacy of the archival data.

By leveraging the security scanning capabilities of S4E, users can detect and address vulnerabilities like SSRF in Ligeo Archives Ligeo Basics. Our platform provides in-depth vulnerability assessments, detailed reports, and practical remediation guidance, helping institutions protect their digital archives against cyber threats. Membership offers continuous monitoring, expert support, and the assurance that your digital assets are safeguarded against emerging vulnerabilities, enhancing your cybersecurity posture.

 

References

Solution Advice
  1. Update Ligeo Archives Ligeo Basics to the latest version with the SSRF vulnerability patched.
  2. Implement strict input validation and sanitization to ensure that only legitimate file paths or URLs are processed in the download functionality.
  3. Employ network level controls to restrict outbound requests from the server, limiting the potential impact of SSRF attacks.
  4. Regularly review and update security policies and practices to address new and evolving threats.
  5. Conduct periodic security audits and penetration testing to identify and remediate vulnerabilities in a timely manner.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.