Files
CVEs-PoC/2020/CVE-2020-13484.md
T
2024-05-25 21:48:12 +02:00

782 B

CVE-2020-13484

Description

Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.

POC

Reference

No PoCs from references.

Github