Impact
The vulnerability resides in the Upload method of the ProductController, where an attacker can supply a crafted params.url value that causes the server to fetch arbitrary URLs. This provides a server‑side request forgery that allows a remote attacker to make the application send requests to internal or external hosts, potentially exfiltrating data or interacting with services that are otherwise inaccessible.
Affected Systems
OpenBoxes versions 0.9.7 and earlier are affected. The vendor, OpenBoxes, released a hot‑fix 0.9.8‑hotfix1 and a standard 0.9.8 release that contain the mitigation. These patches include commit a599007325efe780a21b3537ecce3ca25635c926. Only OpenBoxes products listed in the CPE (openboxes:openboxes) were impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate risk, and the EPSS is not available, but the vulnerability has been publicly disclosed and can be exploited remotely. It is not currently listed in the CISA KEV catalog, yet the public exploit artifacts on GitHub and VULDB indicate that an attacker can achieve SSRF without special privileges. Therefore, the risk remains significant for systems still running the affected versions.
OpenCVE Enrichment