PT-2024-19273 · Unknown · Whoogle Search

Sylwia Budzynska

·

Published

2024-01-18

·

Updated

2024-03-14

·

CVE-2024-22205

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Whoogle Search versions 0.8.3 and prior
Description Whoogle Search is a self-hosted metasearch engine. The window endpoint does not sanitize user-supplied input from the location variable and passes it to the send method, which sends a GET request, leading to a server-side request forgery. This issue allows for crafting GET requests to internal and external resources on behalf of the server, enabling access to resources on the internal network that the server has access to, even if these resources are not accessible on the internet.
Recommendations For versions 0.8.3 and prior, update to version 0.8.4 to resolve the issue. As a temporary workaround, consider restricting access to the window endpoint until a patch is available. Avoid using the location variable in the affected window endpoint until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-22205
GHSA-3Q6G-QMPX-RQW4
PYSEC-2024-18

Affected Products

Whoogle Search