Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107273

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 07, 2026
Vendor unknown

Description

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which the default dialer deny list does not block, to read service responses and enumerate internal hosts and ports through error messages.

References