An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.Referenceshttps://everywall.github.io/https://packetstormsecurity.com/files/177506/Ladder-0.0.21-Server-Side-Request-Forgery.html