Impact
The Meeting Room Booking System, a PHP-based application, contains a Server‑Side Request Forgery vulnerability in its import functionality that allows an authenticated user to supply a private or local URI, which the server fetches without validation. This flaw exposes internal resources or directories to the attacker, potentially enabling data exfiltration or further exploitation. The weakness corresponds to CWE‑918.
Affected Systems
All releases of MRBS prior to version 1.12.2 are impacted, including MRBS code base versions older than 1.12.2 that are commonly deployed for room booking management.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while the EPSS score is not available, the risk remains significant. The vulnerability can be triggered through the import interface with any supplied URI, requiring only the ability to use that feature—likely available to regular authenticated users—thus making exploitation relatively easy. The flaw is not listed in the CISA KEV catalog, but because it allows unauthorized access to internal content, rapid remediation is advised.
OpenCVE Enrichment