HackerOne Disclosed Reports - 2026-05-30

0 Replies, 12 Views

Logo
Medium
resolved

Blind POST SSRF via Web Push Notification Endpoint


Bug reported by Miso Poop was disclosed at May 30, 2026, 4:47 pm   |   Server-Side Request Forgery (SSRF)

A vulnerability was discovered in phpBB 4.0.0-alpha1 that allowed registered users to register arbitrary URLs as their Web Push notification endpoint. The endpoint URL was stored without validation and later used by the phpBB server to send outbound HTTP POST requests, potentially leading to blind POST server-side request forgery (SSRF) vulnerabilities.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)