Description
Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery.

This issue affects Weoll: before 3.2.45.44.
Published: 2026-09-23
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery exposing JWT tokens
Action: Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery that allows an attacker to make the authenticated server send arbitrary HTTP requests. The misconfiguration permits the attacker to obtain the JWT authentication token used by Global IT Informatics' Weoll application, leading to a confidentiality breach of credential material.

Affected Systems

Global IT Informatics Technology Services Inc. Weoll, versions prior to 3.2.45.44.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is unknown, but the vulnerability is publicly documented. Because it is a network exposed SSRF flaw, any external attacker who can reach the affected endpoint could potentially execute the exploit, and it is likely that the application does not have strict outbound request validation.

Generated by OpenCVE AI on September 23, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Weoll to version 3.2.45.44 or later to address the SSRF flaw.
  • Restrict the application’s outbound network connections to only trusted destinations, or implement a proxy that filters requests to prevent SSRF.
  • Validate and sanitize all URLs or request parameters before the server makes outbound requests, ensuring that only safe, whitelisted domains are contacted.

Generated by OpenCVE AI on September 23, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Global It Informatics Technology Services
Global It Informatics Technology Services weoll
Vendors & Products Global It Informatics Technology Services
Global It Informatics Technology Services weoll

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44.
Title SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Global It Informatics Technology Services Weoll
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-23T12:39:30.130Z

Reserved: 2026-08-20T11:44:34.990Z

Link: CVE-2026-77112

cve-icon Vulnrichment

Updated: 2026-09-23T12:39:26.384Z

cve-icon NVD

Status : Deferred

Published: 2026-09-23T13:17:29.680

Modified: 2026-09-23T17:58:00.627

Link: CVE-2026-77112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:36:49Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)