Impact
Zyplayer-Doc versions up to 1.0.0 contain a Server‑Side Request Forgery flaw in the WikiPageWebService.download() method that allows an attacker to instruct the application to fetch arbitrary URLs. This enables the attacker to read data from internal network resources, potentially revealing sensitive information or interacting with services that would otherwise be inaccessible from the public internet.
Affected Systems
The vulnerability affects Zyplayer-Doc installations running any version equal to or less than 1.0.0. No additional vendor or product names are specified in the advisory.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Attackers must be able to send requests to the vulnerable service, so the primary vector is network‑based. Given that the flaw can be exploited by simple HTTP requests, the risk is significant once the vulnerable component is reachable, yet the absence of exploitation data suggests a moderate to high likelihood of exploitation in environments where outbound restrictions are insufficient.
OpenCVE Enrichment