Impact
An attacker can supply an arbitrary URL to the sat_proxy.php script in Zenith Satellite Tracker 1.0, causing the server to execute a curl request to the supplied address. This server‑side request forgery allows the attacker to reach internal network endpoints or cloud metadata services, potentially exposing confidential data or providing a foothold for subsequent attacks. The vulnerability is a classic input‑validation flaw identified as CWE‑918 and results in unauthorized external network requests from the server's host.
Affected Systems
The vulnerability affects Zenith Satellite Tracker version 1.0. No additional vendor or product information is listed beyond that version; users operating this specific release must verify whether they are running it or a derivative that includes the sat_proxy.php component.
Risk and Exploitability
The CVSS score of 9.8 indicates a high‑severity risk, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker would need to target the exposed sat_proxy.php endpoint and supply a crafted URL; no authentication is required, making the attack path straightforward from the public network. The impact can range from sensitive data disclosure to pivoting toward internal resources, depending on the server’s network environment.
OpenCVE Enrichment