SSRF in Export template to ActiveCampaign
Medium
S
Stripo Inc
Submitted None
Actions:
Reported by
c1kada
Vulnerability Details
Technical details and impact analysis
## Summary:
I found a SSRF vulneranility in export template to email marketing platform (ActiveCampaign).
## Steps To Reproduce:
[add details for how we can reproduce the issue]
1. Login to your account in
1. Go to `https://my.stripo.email/cabinet/#/templates/`
1. Click on `Create your first mail` & select one template
1. Export
1. Click on `ActiveCampaign`
1. Insert your server address in `API URL `and a fake string in API Key
1. Now Click on Export and see your `server logs`
{F654075}
## PoC Video
{F654076}
## Impact
The export template to ActiveCampaign is vulnerable to a SSRF vulnerability. The vulnerability allows an attacker to make arbitrary HTTP/HTTPS requests.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Server-Side Request Forgery (SSRF)