CVE-2026-92815
YüksekTeknik Veri (Otomatik)
- CVSS Skoru
- 7.5
- EPSS
- —
- CWE
- CWE-918
- KEV Durumu
- Hayır
changedetection.io 0.60.6 sürümüne kadar, tarayıcı adımlarındaki Goto URL işlemini doğrulamayı başaramaz, bu da kimlik doğrulamaları yapılmamış saldırganların dahili adreslere erişmesine olanak tanır. Saldırganlar, optional_value parametresinde keyfi dahili URL'ler sağlayarak kısıtlı ağ konumlarından yanıtları alabilir.
Orijinal açıklama (İngilizce)
changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations.
Referanslar
- https://github.com/dgtlmoon/changedetection.io
- https://github.com/dgtlmoon/changedetection.io/blob/0.60.6/changedetectionio/browser_steps/browser_steps.py#L182-L192
- https://github.com/geo-chen/oss/blob/main/changedetection.io.md#finding-2-ssrf-via-browser-step-goto-url-action-bypasses-the-ssrf-guard-guard-only-applied-to-the-main-watch-url
- https://www.vulncheck.com/advisories/changedetection-io-through-0.60.6-ssrf-via-browser-step-goto-url
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
