Loading HuntDB...

SSRF external interaction

Low
S
Stripo Inc
Submitted None
Reported by 0xcharan

Vulnerability Details

Technical details and impact analysis

Server-Side Request Forgery (SSRF)
hi team, i found ssrf external interaction on your website which is https://my.stripo.email/cabinet/#/login?guid=&tn=&locale=en on chatbox description:- the attacker might cause the server to make connection back to it self or to other web services within the organization infrastructure or to external third party systems steps to reproduce:- 1)navigate to this website https://my.stripo.email/cabinet/#/login?guid=&tn=&locale=en 2))there you can find chat box 3)paste burp collaborator URL or http://pingb.in 4)you will get HTTP request to your server note:-i previously submitted this issues in bug crowd it marked as p4 so i set severity to low and i tested many chat application not all are vulnerable example bug crowd chat system. ## Impact by this vulnerability attacker can map out attack surface

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Server-Side Request Forgery (SSRF)