Loading HuntDB...

SMB SSRF in emblem editor exposes taketwo domain credentials, may lead to RCE

High
R
Rockstar Games
Submitted None

Team Summary

Official summary from Rockstar Games

In this report, the researcher found that by submitting crafted SVG files, he was able to establish a listener on our server that enabled SSRF attacks. This potentially could have been pivoted to carry out more damaging attacks as well. We improved our validation of user-submitted SVG files to prevent this from happening in the future.

Reported by alexbirsan

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$1500.00

Submitted

Weakness

Server-Side Request Forgery (SSRF)