Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-73315 — Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests. | Kitploit
أدوات/GitHubGitHub/bombobombone/cve-2026-73315
Vulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubbombobombone/cve-2026-73315

CVE-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

عرض المستودع
11منذ 20 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2026-73315: SSRF through PayPal certificate URL

XenForo before 2.3.13 fetches the certificate URL supplied by a PayPal REST webhook without restricting its destination.

What happens

The callback handler passes PAYPAL-CERT-URL to XenForo's trusted HTTP reader. It does not require a PayPal hostname and does not block loopback or private-network destinations. A remote request can therefore make the XenForo host fetch an attacker-selected URL.

I confirmed the SSRF with a listener on XenForo 2.3.12. I also tested the signature path with a synthetic certificate and the configured webhook ID. That second result requires knowledge of the webhook ID.

The demonstrated impact is blind server-side HTTP(S) access. Payment forgery is conditional on additional configuration knowledge. XenForo 2.3.13 contains the fix.

Proof of concept

The script signs one synthetic callback with a local test key and points the certificate header at a URL you control:

root@kitploit:~
python poc.py https://xenforo.example REQUEST_KEY 10.00 USD TEST_WEBHOOK_ID https://listener.example/test-cert.pem test-key.pem

The listener must serve the certificate matching test-key.pem.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

تنزيل الأداة