PT-2026-84976 · Ocs Inventory · Ocsreports
CVE-2026-76177
·
Publicado
2026-09-03
·
Atualizado
2026-09-03
CVSS v4.0
7.1
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N |
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele activate endpoint due to insufficient validation of the HTTPS SERV and FILE SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ocsreports