Impact
An SSRF vulnerability exists in the downloadFile function of the PPTUtil.java component of Taoofagi easegen-admin. The flaw allows an attacker to supply a crafted URL, causing the server to perform a request to an arbitrary internal or external address. This can lead to unauthorized data access, internal network reconnaissance, or further exploitation. The weakness is identified as CWE-918.
Affected Systems
All instances of Taoofagi easegen-admin up to commit 8f87936ac774065b92fb20aab55b274a6ea76433 are affected. No specific release numbers are provided because the project uses a rolling release model.
Risk and Exploitability
The CVSS base score of 5.1 denotes moderate severity. There is no EPSS score available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed remotely over the network, requiring only the ability to craft a request to the application. The lack of an official patch or publicly documented workaround increases the risk until the vendor releases a fix.
OpenCVE Enrichment