SMB SSRF in emblem editor exposes taketwo domain credentials, may lead to RCE
High
R
Rockstar Games
Submitted None
Team Summary
Official summary from Rockstar Games
In this report, the researcher found that by submitting crafted SVG files, he was able to establish a listener on our server that enabled SSRF attacks. This potentially could have been pivoted to carry out more damaging attacks as well. We improved our validation of user-submitted SVG files to prevent this from happening in the future.
Actions:
Reported by
alexbirsan
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$1500.00
Submitted
Weakness
Server-Side Request Forgery (SSRF)