Ctrip's vulnerability profile concentrates on its Apollo product line, a travel and hospitality platform with a web-facing service architecture. The observed weakness classes center on input-handling and request-routing security, including improper input validation and server-side request forgery, which are characteristic of backend service exposure in customer-facing travel applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ctrip over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10686CRITICAL An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/healt | Apr 1, 2019 | 10.0 | 30 | NO | NO |
CVE-2020-15170HIGH apollo-adminservice before version 1.7.1 does not implement access controls. If users expose apollo-adminservice to internet(which is not recommended), there are potential security | Sep 10, 2020 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ctrip.
Media articles that mention a CVE ID that affects a product developed by Ctrip — matched by CVE ID, not by vendor name.