An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/users endpoint.
https://statping-ng.github.io/
https://github.com/statping-ng/statping-ng
https://github.com/Ev3rR3d/Statping_Poc/tree/main/CVE-2024-26478