Loading HuntDB...

SSRF in Export template to ActiveCampaign

Medium
S
Stripo Inc
Submitted None
Reported by c1kada

Vulnerability Details

Technical details and impact analysis

Server-Side Request Forgery (SSRF)
## Summary: I found a SSRF vulneranility in export template to email marketing platform (ActiveCampaign). ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. Login to your account in 1. Go to `https://my.stripo.email/cabinet/#/templates/` 1. Click on `Create your first mail` & select one template 1. Export 1. Click on `ActiveCampaign` 1. Insert your server address in `API URL `and a fake string in API Key 1. Now Click on Export and see your `server logs` {F654075} ## PoC Video {F654076} ## Impact The export template to ActiveCampaign is vulnerable to a SSRF vulnerability. The vulnerability allows an attacker to make arbitrary HTTP/HTTPS requests.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Server-Side Request Forgery (SSRF)