Impact
The vulnerability is a server‑side request forgery (SSRF) that allows an attacker to send arbitrary HTTP requests from the Revenue Administration Türkiye's E‑Signature web application to internal destinations. This flaw can expose internal services, leak sensitive data, or facilitate further attacks such as network reconnaissance, but it does not grant code execution or clear‑text access on the host. The vulnerability is listed as CWE‑918, indicating insufficient input validation of URLs and host data.
Affected Systems
The issue affects the Revenue Administration Türkiye's E‑Signature application. All versions from 2.4.4.0 up to, but not including, 2.5.1.0 are vulnerable. Any deployment of these versions should be considered at risk until remedied.
Risk and Exploitability
The CVSS score of 5.4 classifies the weakness as medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower current exploitation pressure. However, the attack vector is likely an unauthenticated WebSocket API, inferred from the title, meaning that a remote attacker could trigger the SSRF without credentials. The risk to confidentiality and integrity of internal resources is moderate, especially if sensitive services are reachable from the application server. Due to the lack of available EPSS data, the exact likelihood of exploitation cannot be quantified, but the medium CVSS indicates that it should be addressed promptly.
OpenCVE Enrichment