PT-2026-83729 · Yaojingang · Geoflow
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
yaojingang GEOFlow versions prior to 2.1.1
Description
A server-side request forgery (SSRF) issue exists that allows remote attackers to manipulate the
endpoint url argument. This occurs within the isValidHttpEndpoint() function located in the app/Services/GeoFlow/GenericHttpEndpointResolver.php file.Recommendations
Update to version 2.1.1.
As a temporary mitigation, restrict access to the
isValidHttpEndpoint() function.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geoflow