Openfire /getFavicon 路径存在SSRF漏洞

2019-10-24 Openfire PoC No

Description

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities