Impact
An authenticated administrator can manipulate the server to issue requests to internal network services that are not exposed through the normal interface, enabling the discovery or interaction with resources that should remain unreachable. This vulnerability is a server‑side request forgery (SSRF) caused by CRLF injection (CWE‑93) and does not, on its own, execute code on the Kiteworks Core server, but it does expose internal services and creates a potential foothold for further attacks.
Affected Systems
Kiteworks Core is the only affected product; version information is not provided in the advisory. Review the vendor’s security notice for details on which releases require the patch.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity. Because the attack requires authenticated administrator privileges, the exploitability is limited to accounts with such rights, but the lack of code execution does not eliminate the risk of data exposure or lateral movement. The EPSS score is not available, and the issue is not listed in any KEV catalog.
OpenCVE Enrichment