Dozzle是Amir Raminfar个人开发者的一个小型轻量级应用程序。 Dozzle 10.5.2之前版本存在代码问题漏洞,该漏洞源于默认部署中POST /api/notifications/test-webhook端点无需身份验证,攻击者可控制URL和请求头,使WebhookDispatcher向目标发送HTTP POST请求并返回响应状态码及最多1MB响应体。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Dozzle prior to 10.5.2 contains a server-side request forgery caused by unauthenticated access to POST /api/notifications/test-webhook forwarding attacker-controlled URLs, letting remote attackers send arbitrary HTTP POST requests and receive response data, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-45298.yaml | POC Details |
No comments yet