Impact
A bug in the updateJiraProjects function of DevaslanPHP project‑management’s Jira Import component allows an attacker to control the host, username, and token arguments, leading to a server‑side request forgery (SSRF). By sending a crafted request to this endpoint, an external actor can cause the application to issue HTTP requests to arbitrary URLs reachable from the host, potentially exposing internal resources or facilitating further attacks. The vulnerability is exploitable remotely and has a CVSS score of 5.1, indicating moderate severity with possible confidentiality or availability impact.
Affected Systems
Versions 1.2.1, 1.2.2, 1.2.3, 1.2.4 and 2.0.0‑beta1 of DevaslanPHP project‑management are vulnerable. The flaw resides in the Jira Import plugin’s /jira‑import code.
Risk and Exploitability
The CVSS score suggests a moderate risk, and with no EPSS data available, the likelihood of exploitation is unknown but the attack can be performed from any remote location that can reach the Jira Import endpoint. Since the vulnerability is public and the vendor has not released a fix, the risk remains present. Monitoring for exploitation attempts and applying a patch as soon as one is available is recommended.
OpenCVE Enrichment