
Disclosure of a Server-Side Request Forgery (SSRF) vulnerability in Inflectra SpiraTeam 7.2.00, detailing the attack vector, impacts, and vendor acknowledgment.
Inflectra SpiraTeam version 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) through the NewsReaderService component.
Server-Side Request Forgery (SSRF)
Inflectra
SpiraTeam 7.2.00
NewsReaderService
Remote
An attacker can send specially crafted requests to the NewsReaderService, prompting the server to make unintended requests. This can lead to the capture of authentication hashes from the host where SpiraTeam is installed.
Inflectra has confirmed the existence of this vulnerability.
Gareth Catterall https://www.anchorsec.co.uk
Users of SpiraTeam 7.2.00 are encouraged update to the latest version of the product.