PT-2026-24807 · Git+2 · Openproject
Adilburak
+1
·
Published
2026-03-11
·
Updated
2026-03-19
·
CVE-2026-31974
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 17.2.0
Description
OpenProject is a web-based project management software. Prior to version 17.2.0, the SMTP test endpoint, accessible via the ''POST /admin/settings/mail notifications'' API endpoint, accepts arbitrary host and port values. This allows an attacker with access to map internal hosts and identify reachable services and ports through timing and error differences in the response. Similarly, creating webhooks pointing to arbitrary IPs results in a Server-Side Request Forgery (SSRF) issue, enabling attackers to scan the internal network. The
host and port parameters of the SMTP test endpoint are vulnerable.Recommendations
Versions prior to 17.2.0 should be updated to version 17.2.0 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openproject