Files
CVEs-PoC/2020/CVE-2020-13484.md
T
2025-09-29 21:09:30 +02:00

899 B

CVE-2020-13484

Description

Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.

POC

Reference

No PoCs from references.

Github