Server-Side Request Forgery (SSRF) in aimeos/aimeos-core
Valid
Reported on
Jul 7th 2021
✍️ Description
Integrated online shop based on Laravel 6 LTS and the Aimeos e-commerce framework this web app is vulnerable for stored SSRF thru svg files
🕵️♂️ Proof of Concept
💥 Impact
This vulnerability is capable SSRF
Occurrences
We have contacted a member of the
aimeos/aimeos-core
team and are waiting to hear back
2 years ago
reopening https://www.huntr.dev/bounties/1625429205812-aimeos/aimeos-laravel/ here for low severity and wrong repo
wrong
The disclosure bounty has been dropped
The fix bounty has been dropped
to join this conversation