Impact
Dromara Skyeye contains a server‑side request forgery that allows an attacker to supply arbitrary URL and key parameters to the editUploadOfficeFileById endpoint. Unauthenticated users can force the server to request internal addresses and overwrite any stored file belonging to any user. The overwrite can then be read via queryFileToShowById, enabling an attacker to place malicious content or gain further foothold into the system. This flaw is a classic case of insecure input handling (CWE‑918) and results in a loss of file integrity and confidentiality, and potentially a full compromise of the compromised user’s data.
Affected Systems
The vulnerability affects the Dromara Skyeye platform. No specific version range is listed in the CNA data, so any deployment using the code prior to commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 may be vulnerable. Administrators should verify the exact build they are running and consult the project’s GitHub repository for the latest patch status.
Risk and Exploitability
The CVSS score of 9.1 indicates a high impact and relatively easy exploitation. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog. The most likely attack vector is via unauthenticated remote network access to the Skyeye web service; the attacker can trigger the SSRF directly by submitting crafted requests. Although the vulnerability is not tied to an existing exploit, the high severity and the nature of the flaw mean that it should be treated as a high priority risk.
OpenCVE Enrichment