Impact
A flaw in the open_graphic_parse endpoint of Privoce VoceChat Server allows an attacker to manipulate the URL parameter, causing the server to send HTTP requests to arbitrary destinations. This results in a server‑side request forgery vulnerability that can lead to disclosure of internal resources, internal network scanning, or the use of the server as a proxy to attack other services.
Affected Systems
Privoce VoceChat Server, versions up to and including 0.5.36 are affected.
Risk and Exploitability
The CVSS score of 6.9 signifies a moderate risk, and the vulnerability has already been publicly disclosed, enabling remote exploitation. EPSS data are unavailable and the flaw is not listed in CISA's KEV catalog. Because the vendor has not issued a patch, the risk remains until remediation steps are taken.
OpenCVE Enrichment