Post Request Injection Vulnerability in HomeBox by SysAdmins Media
CVE-2026-27600

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 March 2026

What is CVE-2026-27600?

HomeBox, an inventory management application by SysAdmins Media, has a vulnerability that allows authenticated users to send HTTP POST requests to arbitrary URLs. This occurs due to the lack of validation on the specified hosts, IP addresses, or ports. As a result, the application can be exploited for internal service enumeration through behavioral changes in the UI, depending on the network state of the target destination. This issue has been addressed in version 0.24.0-rc.1, which mitigates the risk by implementing proper validations.

Affected Version(s)

homebox < 0.24.0-rc.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.