Impact
The vulnerability occurs in a function that handles a URL parameter within the Admin Metadata Endpoint of Shaarli. Manipulating this URL argument allows an attacker to make the server fetch arbitrary resources, enabling a server‑side request forgery (SSRF). The flaw does not lead to arbitrary code execution or direct data exfiltration, but it can be leveraged to probe internal systems, access privileged resources, or carry out further attacks. This injected request capability can be used by a remote actor to execute queries against internal networks or external services.
Affected Systems
Shaarli, the open‑source link shortener, is affected in all releases up to and including version 0.16.3. The fix was introduced in release 0.16.4, so any deployment running a vulnerable version of Shaarli must be updated to 0.16.4 or newer.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The description states that an attacker may manipulate the URL argument to make the server fetch arbitrary resources, allowing server‑side request forgery. Based on this description, it is inferred that the flaw can be triggered remotely without authentication, implying a low barrier to exploitation. An attacker could craft a malicious request to the Metadata endpoint and supply a URL that the server will request, potentially allowing third‑party content retrieval or internal network probing. It is further inferred that if the server processes responses or follows redirects, this could be abused to discover internal hosts.
OpenCVE Enrichment