.. / CVE-2021-27670

Exploit for Appspace 6.2.4 - Server-Side Request Forgery (CVE-2021-27670)

Description:

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

Nuclei Template

View the template here CVE-2021-27670.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-27670.yaml
Copy

References:

https://github.com/Miraitowa70/POC-Notes
https://github.com/ArrestX/--POC
https://github.com/h3110mb/PoCSSrfApp
https://nvd.nist.gov/vuln/detail/CVE-2021-27670
https://github.com/KayCHENvip/vulnerability-poc