Stored Server-Side Request Forgery in mosparo Forms Protection
CVE-2026-41195
5MEDIUM
What is CVE-2026-41195?
The mosparo platform, designed to protect online forms from spam, contains a vulnerability that allows an attacker to exploit the automatic rule package source URL feature. This issue arises when a project member with editor privileges inputs a URL that the server fetches, potentially leading to unauthorized access to internal services. The server's following of HTTP/HTTPS redirects without appropriate restrictions can be manipulated to create a stored SSRF exploit, effectively turning it into a probing tool for internal resources. This vulnerability was addressed in version 1.4.13.
Affected Version(s)
mosparo < 1.4.13
