CyberRota Analysis
AI-GeneratedThe Privoce VoceChat Server versions up to 0.5.36 are vulnerable due to a server-side request forgery (SSRF) flaw in the open_graph::fetch function, which can be exploited by manipulating the URL argument. This high-severity vulnerability allows remote attackers to potentially access internal resources or services, posing a significant risk to affected systems. Organizations using this software should prioritize patching or mitigating this vulnerability, especially given the lack of vendor response to the disclosure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.