VYPR

Satellite Tracker

by Zenith

CVEs (1)

  • CVE-2025-56563Sep 16, 2026
    risk 0.00cvss epss

    A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker…