CRITICAL
Zenith Satellite
CVE published 2026-09-16
CVE-2025-56563
A Server-Side Request Forgery vulnerability exists in Zenith Satellite Tracker 1.0, specifically in the sat_proxy.php script. This script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. Consequently, an unauthenticated remote attacker can leverage this vulnerability to make arbitrary HTTP and HTTPS requests from the server t [truncated]