Skip to content

SSRF @ links.py #2

@danielgerb

Description

@danielgerb

SSRF issue exists @ links.py in branch master

The application sends a request to a remote server, for some resource, using get in /scripts/validate/links.py:167. However, an attacker can control the target of the request, by sending a URL or other data in argv at /scripts/validate/links.py:271.

Namespace: danielgerb
Repository: public-API
Repository Url: https://github.com/danielgerb/public-API
CxAST-Project: danielgerb/public-API
CxAST platform scan: 1c36dc32-6289-4fa2-949a-3fd6c4cf5551
Branch: master
Application: public-API
Severity: MEDIUM
State: TO_VERIFY
Status: NEW
CWE: 918
Lines: 271


References
Read more

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions