PT-2026-4317 · Fog · Fog

Soptikha2

·

Publicado

2026-01-23

·

Atualizado

2026-01-28

·

CVE-2026-24138

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FOG versions 1.5.10.1754 and below
Description FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated Server-Side Request Forgery (SSRF) condition in the getversion.php file. This can be triggered by providing a user-controlled URL parameter. The issue allows fetching both internal websites and files on the machine running FOG. The condition appears to be reachable without an authenticated web session when the request includes newService=1. The API endpoint involved is getversion.php and the vulnerable parameter is the URL parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24138
GHSA-79XW-C2QX-G7XJ

Produtos afetados

Fog