PT-2026-22237 · Psi Probe · Psi Probe
Ana10Gy
+1
·
Published
2026-02-26
·
Updated
2026-03-03
·
CVE-2026-3270
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PSI Probe versions up to 5.3.0
Description
A flaw exists in PSI Probe that allows for server-side request forgery. This issue stems from the
lookup function within the Whois.java file, located in the psi-probe-core/src/main/java/psiprobe/tools component. The manipulation of this function can lead to unauthorized requests being made on the server. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed. The vendor was notified but did not provide a response.Recommendations
Versions prior to 5.3.0 should be used.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Psi Probe