Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-73315 — Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests. | Kitploit
도구/GitHubGitHub/bombobombone/cve-2026-73315
Vulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubbombobombone/cve-2026-73315

CVE-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

저장소 보기
1120일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-73315: SSRF through PayPal certificate URL

XenForo before 2.3.13 fetches the certificate URL supplied by a PayPal REST webhook without restricting its destination.

What happens

The callback handler passes PAYPAL-CERT-URL to XenForo's trusted HTTP reader. It does not require a PayPal hostname and does not block loopback or private-network destinations. A remote request can therefore make the XenForo host fetch an attacker-selected URL.

I confirmed the SSRF with a listener on XenForo 2.3.12. I also tested the signature path with a synthetic certificate and the configured webhook ID. That second result requires knowledge of the webhook ID.

The demonstrated impact is blind server-side HTTP(S) access. Payment forgery is conditional on additional configuration knowledge. XenForo 2.3.13 contains the fix.

Proof of concept

The script signs one synthetic callback with a local test key and points the certificate header at a URL you control:

root@kitploit:~
python poc.py https://xenforo.example REQUEST_KEY 10.00 USD TEST_WEBHOOK_ID https://listener.example/test-cert.pem test-key.pem

The listener must serve the certificate matching test-key.pem.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

도구 다운로드