Impact
A missing authorization check on the /approval-flow/webhook/test endpoint allows any authenticated user to trigger server-side requests to arbitrary URLs. This blind server‑side request forgery (SSRF) can be used to probe internal network addresses by observing success or failure responses, potentially exposing sensitive resources. The weakness is cataloged as CWE‑862, Unauthorized Access.
Affected Systems
The vulnerability affects CordysCRM version 1.9.3 distributed by 1Panel-dev. No other versions or vendors are listed as affected in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact. No EPSS data is available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting that exploit activity may be limited. Attackers must first authenticate to the application, but once authenticated they can exploit the endpoint without restriction. The attack vector is a POST request to /approval-flow/webhook/test; because the response does not expose payload content, only the success or failure of the request is observable, making it a blind SSRF.
OpenCVE Enrichment