SSRF in Export template to ActiveCampaign
Medium
Vulnerability Details
## Summary:
I found a SSRF vulneranility in export template to email marketing platform (ActiveCampaign).
## Steps To Reproduce:
[add details for how we can reproduce the issue]
1. Login to your account in
1. Go to `https://my.stripo.email/cabinet/#/templates/`
1. Click on `Create your first mail` & select one template
1. Export
1. Click on `ActiveCampaign`
1. Insert your server address in `API URL `and a fake string in API Key
1. Now Click on Export and see your `server logs`
{F654075}
## PoC Video
{F654076}
## Impact
The export template to ActiveCampaign is vulnerable to a SSRF vulnerability. The vulnerability allows an attacker to make arbitrary HTTP/HTTPS requests.
Actions
View on HackerOneReport Stats
- Report ID: 754025
- State: Closed
- Substate: resolved
- Upvotes: 13