Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-73315 — Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests. | Kitploit
उपकरण/GitHubGitHub/bombobombone/cve-2026-73315
Vulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubbombobombone/cve-2026-73315

CVE-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

रिपॉजिटरी देखें
1120 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2026-73315: SSRF through PayPal certificate URL

XenForo before 2.3.13 fetches the certificate URL supplied by a PayPal REST webhook without restricting its destination.

What happens

The callback handler passes PAYPAL-CERT-URL to XenForo's trusted HTTP reader. It does not require a PayPal hostname and does not block loopback or private-network destinations. A remote request can therefore make the XenForo host fetch an attacker-selected URL.

I confirmed the SSRF with a listener on XenForo 2.3.12. I also tested the signature path with a synthetic certificate and the configured webhook ID. That second result requires knowledge of the webhook ID.

The demonstrated impact is blind server-side HTTP(S) access. Payment forgery is conditional on additional configuration knowledge. XenForo 2.3.13 contains the fix.

Proof of concept

The script signs one synthetic callback with a local test key and points the certificate header at a URL you control:

root@kitploit:~
python poc.py https://xenforo.example REQUEST_KEY 10.00 USD TEST_WEBHOOK_ID https://listener.example/test-cert.pem test-key.pem

The listener must serve the certificate matching test-key.pem.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

टूल डाउनलोड करें