Description
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search terms, which can be controlled by attackers to trigger outbound requests to arbitrary domains. This issue has been patched in version 4.7.0.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
CWE-922: Insecure Storage of Sensitive Information
Product status
References
github.com/...Wallos/security/advisories/GHSA-hhjq-82f8-m6rc
github.com/...ommit/e87387f0ebb540cd33e6dfda7181db9db650ecef