![]() |
|
HackerOne Disclosed Reports - 2025-12-01 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-12-01 (/Thread-HackerOne-Disclosed-Reports-2025-12-01) |
HackerOne disclosed reports - 2025-12-01 - hashXploiter - 12-02-2025
Critical
resolved [my.stripo.email] Blind SSRF Vulnerability in Stripo App Export via Missing Endpoints Export Email Message to ZapierBug reported by ꦄꦤ꧀ꦢꦿꦶ was disclosed at December 1, 2025, 8:22 am | Server-Side Request Forgery (SSRF) A critical Blind SSRF (Server-Side Request Forgery) vulnerability was identified in the export service of the Stripo app. The vulnerability existed in the endpoint `/exportservice/v3/exports/WEBHOOK/accounts`, where malicious input could be provided in the `webhookUrl` parameter, triggering SSRF and allowing the server to make unauthorized HTTP requests to attacker-controlled systems. |