Illia Cloud illia-Builder Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in Illia Cloud illia-Builder versions prior to 4.8.5. This vulnerability allows authenticated users to send arbitrary requests to internal services via the API. Exploitation of this vulnerability could enable an attacker to enumerate open ports based on response discrepancies and interact with internal services.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal services, allowing for potential data exfiltration or manipulation. Additionally, the vulnerability could be used to perform port scanning activities, identifying open ports and services running on the internal network.

Added: Oct 17, 2025, 4:18 PM
Updated: Oct 17, 2025, 4:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.