Impact
The add_watch_ui_snapshot function in the preview endpoint of changedetection.io can be manipulated by supplying a crafted URL. This allows an attacker to trigger arbitrary outbound HTTP requests from the server, a classic server-side request forgery (SSRF) flaw. The vulnerability can be exploited remotely, and a public exploit has been released, meaning attackers can easily target vulnerable installations.
Affected Systems
This issue affects all releases of dgtlmoon changedetection.io prior to version 0.60.1, including the code base up to commit 50389b07. The fix is included in the 0.60.1 release, and upgrading to that version or later removes the flaw.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is moderate, but the lack of an EPSS score and its absence from the KEV catalog do not diminish the risk because the flaw is exploitable remotely and a public exploit is available. Attackers can use SSRF to reach internal networks or third‑party services, potentially exposing sensitive data or enabling further attacks. The high attack surface and lack of authentication mitigate factors make timely remediation critical.
OpenCVE Enrichment