Impact
This vulnerability permits an authenticated Pentestify user to induce the server to perform arbitrary outbound HTTP GET requests during the PDF export process. By supplying unvalidated URLs in the finding images or client_logo fields, the headless browser used by the report renderer requests those URLs on behalf of the server. The resulting requests could reveal sensitive internal resources, exfiltrate data, or be used for further exploitation, compromising confidentiality and integrity of the instance.
Affected Systems
Pentestify versions prior to 1.1.0 are affected. The vulnerability exists in the PDF export component used by authenticated users. Any deployment of Pentestify before the 1.1.0 release is vulnerable regardless of role or scope of the user.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium impact, while the EPSS score of less than 1% denotes a very low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. The attack requires authentication and occurs via the PDF export feature; an attacker must first obtain valid user credentials to trigger manipulated image URLs that the server fetches during report rendering.
OpenCVE Enrichment