Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 3 min 136 bronnen 2 kritiek 7 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-107273

MEDIUM · 4.3 CVSS Gepubliceerd: CWE-918

Beschrijving

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.

References