PT-2026-23824 · Wallos · Wallos

Ellite

·

Published

2026-03-07

·

Updated

2026-03-11

·

CVE-2026-30839

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.6.2
Description Wallos is a self-hostable personal subscription tracker. Versions prior to 4.6.2 contain a Server-Side Request Forgery (SSRF) condition in the testwebhooknotifications.php file. The application does not properly validate the target URL against private or reserved IP ranges, allowing an attacker to potentially read sensitive information from internal resources. The server's response to the crafted request is then returned to the attacker. The vulnerable component is the testwebhooknotifications.php file.
Recommendations Update to version 4.6.2 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-30839
GHSA-X4QP-XM2C-VQG9

Affected Products

Wallos