Impact
The vulnerability is a server-side request forgery in the webhook feature of WGDashboard. Whitelisted authenticated users can send arbitrary HTTP requests and read the responses, allowing them to reach internal network resources or pull data from the application. This flaw corresponds to CWE‑918 and can lead to unauthorized network access or data exfiltration, potentially facilitating further attacks if the returned content is processed by the system.
Affected Systems
The flaw affects WGDashboard versions 4.2.3 and earlier released by the WGDashboard vendor. Any deployment using those releases is susceptible.
Risk and Exploitability
Because the attack requires authentication, the threat is most relevant when user credentials are compromised or privileges are excessive. No CVSS score is listed, and EPSS is not available, but the absence of a KEV listing does not mitigate the inherent risk. Attackers could exploit the service to query internal hosts, potentially exposing sensitive data or creating a pivot point for lateral movement.
OpenCVE Enrichment