According to the K2 Security Assessment and Penetration Testing 2020 results, one item with medium severity of the pen test of October 2019 remained open after the retest in January 2020. It was supposed to be mitigated during software updates in the course of 2020.
Does anyone know if they have eliminated this server-side request forgery issue within a specific SmartForms control allowing an attacker to discover internal endpoints?