PT-2026-70142 · Apioo · Apioo Fusio
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apioo Fusio version 8.8.3
Description
An authenticated user with the consumer role can trigger server-side request forgery by registering a webhook URL that points to an internal host. The webhook registration endpoint validates URL syntax using
FILTER VALIDATE URL but fails to implement an IP or host denylist. Consequently, when the registered event is triggered, the server sends an HTTP POST request to the specified internal address.Recommendations
Update Apioo Fusio version 8.8.3 to a version that implements a proper IP or host denylist for webhook registrations.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apioo Fusio