Логотип exploitDog
bind:CVE-2025-9821
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-9821

Количество 2

Количество 2

nvd логотип

CVE-2025-9821

3 месяца назад

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html  for more information on SSRF and its fix.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-hj6f-7hp7-xg69

3 месяца назад

Mautic vulnerable to SSRF via webhook function

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-9821

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html  for more information on SSRF and its fix.

CVSS3: 2.7
0%
Низкий
3 месяца назад
github логотип
GHSA-hj6f-7hp7-xg69

Mautic vulnerable to SSRF via webhook function

CVSS3: 2.7
0%
Низкий
3 месяца назад

Уязвимостей на страницу