Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-48590 — Disclosure of a Server-Side Request Forgery (SSRF) vulnerability in Inflectra SpiraTeam 7.2.00, detailing the attack vector, impacts, and vendor acknowledgment. | Kitploit
Tools/GitHubGitHub/gcatt-as/cve-2024-48590
ReconnaissanceVulnerability AnalysisExploitationInformation GatheringWeb Security
GitHubgcatt-as/cve-2024-48590

CVE-2024-48590

Disclosure of a Server-Side Request Forgery (SSRF) vulnerability in Inflectra SpiraTeam 7.2.00, detailing the attack vector, impacts, and vendor acknowledgment.

View Repository
31 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-48590

Vulnerability Disclosure: SSRF in Inflectra SpiraTeam 7.2.00

Description

Inflectra SpiraTeam version 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) through the NewsReaderService component.

Vulnerability Type

Server-Side Request Forgery (SSRF)

Vendor

Inflectra

Affected Product

SpiraTeam 7.2.00

Affected Component

NewsReaderService

Attack Type

Remote

Impacts

  • Escalation of Privileges: Allows attackers to potentially gain higher access levels.
  • Information Disclosure: Exposes sensitive data from the host system.

Attack Vectors

An attacker can send specially crafted requests to the NewsReaderService, prompting the server to make unintended requests. This can lead to the capture of authentication hashes from the host where SpiraTeam is installed.

References

  • OWASP: Server-Side Request Forgery

Vendor Acknowledgment

Inflectra has confirmed the existence of this vulnerability.

Discoverer

Gareth Catterall https://www.anchorsec.co.uk

Note

Users of SpiraTeam 7.2.00 are encouraged update to the latest version of the product.

Download Tool