Impact
Kiteworks Secure Data Forms versions prior to 9.5.0 contain a server‑side request forgery flaw that allows an unauthenticated remote attacker to compel the application to perform arbitrary outbound HTTP requests and to retrieve the responses. This can enable the attacker to probe or exfiltrate data from internal‑only services or any resource reachable from the host, potentially compromising the confidentiality of internal data and the availability of those services. The weakness is a classic input‑validation flaw (CWE‑918).
Affected Systems
The affected product is Kiteworks Secure Data Forms. All releases older than 9.5.0 are vulnerable; no specific sub‑versions are listed, so any deployment built before the 9.5.0 release is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk level. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it from any network using unauthenticated access to the web interface; the exploitation path requires only sending a specially crafted request to the server, after which the server will forward the request to an arbitrary destination and send the response back to the attacker. Because the attack is trivial to trigger, the risk to organizations that expose the server to untrusted networks is significant.
OpenCVE Enrichment