CyberRota Analysis
AI-GeneratedThe HTML-to-PDF Endpoint in projeto-siga versions up to 11.1.1 is vulnerable to server-side request forgery due to improper handling of the argument in the DownloadExterno.getUrl function. This vulnerability allows remote attackers to manipulate requests, potentially leading to unauthorized access to internal resources. Organizations using this software should prioritize remediation to mitigate the risk of exploitation, especially if they handle sensitive data or operate in regulated environments.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.