Impact
Zyplayer‑Doc versions up to 1.0.0 contain a Server‑Side Request Forgery flaw in the WikiPageWebService.download() method that allows an attacker to instruct the application to fetch arbitrary URLs. This capability lets an attacker read data from internal network resources or interact with services that would otherwise be unreachable from the public internet, potentially exposing sensitive information or enabling lateral movement.
Affected Systems
The vulnerability affects Zyplayer‑Doc installations running any version equal to or less than 1.0.0. No additional vendor or product names are specified in the advisory. The flaw resides in the WikiPageWebService.download() endpoint, which is part of the web service component of Zyplayer‑Doc.
Risk and Exploitability
An EPSS score of <1% and a CVSS score of 9.1 indicate a critical severity but a low current likelihood of exploitation. The flaw can be triggered via simple HTTP requests to the vulnerable endpoint, so the primary attack vector is network‑based with the attacker needing direct reach to the Zyplayer‑Doc service. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread or known active exploitation at this time.
OpenCVE Enrichment