Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-73315 — Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests. | Kitploit
Ferramentas/GitHubGitHub/bombobombone/cve-2026-73315
Vulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubbombobombone/cve-2026-73315

CVE-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

Ver Repositório
11há 20 diasAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

CVE-2026-73315: SSRF through PayPal certificate URL

XenForo before 2.3.13 fetches the certificate URL supplied by a PayPal REST webhook without restricting its destination.

What happens

The callback handler passes PAYPAL-CERT-URL to XenForo's trusted HTTP reader. It does not require a PayPal hostname and does not block loopback or private-network destinations. A remote request can therefore make the XenForo host fetch an attacker-selected URL.

I confirmed the SSRF with a listener on XenForo 2.3.12. I also tested the signature path with a synthetic certificate and the configured webhook ID. That second result requires knowledge of the webhook ID.

The demonstrated impact is blind server-side HTTP(S) access. Payment forgery is conditional on additional configuration knowledge. XenForo 2.3.13 contains the fix.

Proof of concept

The script signs one synthetic callback with a local test key and points the certificate header at a URL you control:

root@kitploit:~
python poc.py https://xenforo.example REQUEST_KEY 10.00 USD TEST_WEBHOOK_ID https://listener.example/test-cert.pem test-key.pem

The listener must serve the certificate matching test-key.pem.

References

  • CVE record
  • VulnCheck advisory
  • XenForo 2.3.13 release

Discovered by Marco Paciaroni (BomboBombone).

Baixar ferramenta