Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server...
Moderate severity
Unreviewed
Published
Jun 10, 2025
to the GitHub Advisory Database
•
Updated Jun 17, 2025
Description
Published by the National Vulnerability Database
Jun 10, 2025
Published to the GitHub Advisory Database
Jun 10, 2025
Last updated
Jun 17, 2025
Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.
References