PT-2026-94087 · Dgtlmoon+1 · Changedetection.Io
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
changedetection.io versions prior to 0.60.7
Description
An issue exists where the software fails to validate the Goto URL action within browser steps. This allows unauthenticated attackers to access internal network addresses by providing arbitrary internal URLs through the
optional value parameter, enabling the retrieval of responses from restricted locations.Recommendations
Update changedetection.io to version 0.60.7 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Changedetection.Io