SSRF external interaction

Disclosed: 2020-12-11 12:56:40 By 0xcharan To stripo
Low
Vulnerability Details
hi team, i found ssrf external interaction on your website which is https://my.stripo.email/cabinet/#/login?guid=&tn=&locale=en on chatbox description:- the attacker might cause the server to make connection back to it self or to other web services within the organization infrastructure or to external third party systems steps to reproduce:- 1)navigate to this website https://my.stripo.email/cabinet/#/login?guid=&tn=&locale=en 2))there you can find chat box 3)paste burp collaborator URL or http://pingb.in 4)you will get HTTP request to your server note:-i previously submitted this issues in bug crowd it marked as p4 so i set severity to low and i tested many chat application not all are vulnerable example bug crowd chat system. ## Impact by this vulnerability attacker can map out attack surface
Actions
View on HackerOne
Report Stats
  • Report ID: 1023920
  • State: Closed
  • Substate: resolved
  • Upvotes: 21
Share this report