Impact
The vulnerability is a server‑side request forgery that allows an attacker to make the authenticated server send arbitrary HTTP requests. The misconfiguration permits the attacker to obtain the JWT authentication token used by Global IT Informatics' Weoll application, leading to a confidentiality breach of credential material.
Affected Systems
Global IT Informatics Technology Services Inc. Weoll, versions prior to 3.2.45.44.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is unknown, but the vulnerability is publicly documented. Because it is a network exposed SSRF flaw, any external attacker who can reach the affected endpoint could potentially execute the exploit, and it is likely that the application does not have strict outbound request validation.
OpenCVE Enrichment