CVE-2021-47703

HIGH

OpenBMCS 2.4 phpQuery.php - ip Parameter Server-Side Request Forgery

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47703. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated SSRF vulnerability in OpenBMCS 2.4 by sending a crafted POST request to '/php/query.php' with a manipulated 'ip' parameter, forcing the server to make arbitrary HTTP requests. The provided HTTP request and response confirm the vulnerability's existence and behavior.

Description

OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/50670

This exploit demonstrates an unauthenticated SSRF vulnerability in OpenBMCS 2.4 by sending a crafted POST request to '/php/query.php' with a manipulated 'ip' parameter, forcing the server to make arbitrary HTTP requests. The provided HTTP request and response confirm the vulnerability's existence and behavior.

Classification
Working Poc 90%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Reliable
Target: OpenBMCS 2.4
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit
https://www.exploit-db.com/exploits/50670
Product product
https://www.openbmcs.com
Exploit, Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5694.php

Scores

CVSS v3 7.2
EPSS 0.0027
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
OPEN BMCS/OpenBMCS 2.4
openbmcs/openbmcs 2.4
Published Dec 09, 2025
Tracked Since Feb 18, 2026