Server Side Request Forgery (SSRF) via Analytics Reports

Disclosed: 2023-12-08 18:09:11 By mega7 To security
Critical
Vulnerability Details
Hello Gents, I would like to report an issue where attackers are able to read internal files via an SSRF vulnerability. ## Proof of concept + ███ ## Impact SSRF. Thanks and have a nice day!
Actions
View on HackerOne
Report Stats
  • Report ID: 2262382
  • State: Closed
  • Substate: resolved
  • Upvotes: 446
Share this report