Vendor
The projeto-siga siga application is vulnerable to server-side request forgery (SSRF) via the DownloadExterno.getUrl function, allowing unauthenticated remote attackers to trigger unauthorized requests.