CVE-2020-25788 | Tiny RSS 17.4/829d478f Error Message init.php $_REQUEST["url"] inclusion of functionality from untrusted control sphere
A vulnerability classified as critical was found in Tiny RSS 17.4/829d478f. Affected is an unknown function of the file plugins/af_proxy_http/init.php of the component Error Message Handler. Executing manipulation of the argument $_REQUEST["url"] can lead to inclusion of functionality from untrusted control sphere.
The identification of this vulnerability is CVE-2020-25788. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.