CVE-2023-46945
The vulnerability is a server‑side request forgery (SSRF) that lets an attacker send arbitrary HTTP requests from the affected QD 20230821 system. This could expose internal network resources or sensitive data. It is rated critical because it is exploitable over the network without authentication or user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
QD 20230821 (qd-today qd) – the QD 20230821 product, used by organizations running the QD application.
Real-world impact
An attacker could use the SSRF to reach internal services, read confidential data, or pivot to other systems on the network.
Why this severity
The CVSS score of 9.1 reflects that the flaw is network‑exploitable, requires no privileges, and can compromise confidentiality and integrity, but does not affect availability.
What to do about it
- ›Monitor the vendor for updates and apply any released patches as soon as they become available.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Apr 8, 2026 · Apr 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 25, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- gist.github.com/kurokoleung/5b36b2013a54ada…third party advisory
- qd-today.github.io/qd/product