CyberRota Analysis
AI-GeneratedA server-side request forgery vulnerability exists in kLOsk adloop versions up to 0.9.0, specifically in the _validate_urls function of the write.py file, which can be exploited remotely through manipulated URL arguments. Organizations using this software should prioritize upgrading to version 0.10.0 to mitigate potential exploitation, as the vulnerability is now publicly known. Immediate action is recommended to protect against potential unauthorized access and data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the argument final_url results in server-side request forgery. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 0.10.0 is able to resolve this issue. The patch is named 217399723e3a2fb39389e5355d49ed80aaf9ea7c. Upgrading the affected component is advised.