Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.
History

Fri, 31 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the server-side headless browser fetches while rendering the report.
Title Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs
First Time appeared Ccyl13
Ccyl13 pentestify
Weaknesses CWE-918
CPEs cpe:2.3:a:ccyl13:pentestify:*:*:*:*:*:*:*:*
Vendors & Products Ccyl13
Ccyl13 pentestify
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-07-31T15:06:05.441Z

Reserved: 2026-07-03T11:24:39.241Z

Link: CVE-2026-59231

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.