Description
Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to version 1.1.0 or higher. The fix was not tagged: the earliest tagged release containing it is v1.1.1.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report. | |
| Title | Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs | |
| First Time appeared |
Ccyl13
Ccyl13 pentestify |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ccyl13:pentestify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ccyl13
Ccyl13 pentestify |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-07-31T15:06:05.441Z
Reserved: 2026-07-03T11:24:39.241Z
Link: CVE-2026-59231
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses