CyberRota Analysis
AI-GeneratedA server-side request forgery vulnerability exists in UTMStack versions prior to 11.2.16, allowing authenticated attackers to exploit the PdfService.downloadPdf() method and access arbitrary internal resources by manipulating an unvalidated URL parameter. This can lead to the exposure of sensitive internal data, including information from backend endpoints and cloud instance metadata, through generated PDF reports. Organizations using UTMStack should prioritize patching this vulnerability to mitigate the risk of data leakage.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenSearch cluster, or the cloud instance-metadata service, exposing sensitive internal data rendered into the returned PDF.