Server-Side Request Forgery (SSRF) in kalcaddle/kodexplorer
Reported on
Jun 20th 2021
✍️ Description
SSRF protection bypass via crafted payload which leads to SSRF.
🕵️♂️ Proof of Concept
Payload:
2130706433
This is the decimal way of representing localhost which resolves to localhost.
💥 Impact
This vulnerability is capable of SSRF.
Occurrences
The current settings are allowed to be obtained through URL,