CVE-2024-39713
HIGH EXPLOITED NUCLEIRocket.Chat < 6.10.1 - Server-Side Request Forgery via Twilio Webhook Endpoint
Title source: llmExploitation Summary
CVE-2024-39713 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including typical-pashochek, blackcodersec. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a functional Python script and Nuclei template that exploit an SSRF vulnerability in Rocket.Chat's Twilio webhook endpoint. The exploit sends a crafted POST request with a malicious MediaUrl0 parameter to trigger an SSRF.
Description
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Exploits (2)
The repository contains a functional Python script and Nuclei template that exploit an SSRF vulnerability in Rocket.Chat's Twilio webhook endpoint. The exploit sends a crafted POST request with a malicious MediaUrl0 parameter to trigger an SSRF.
The repository contains a functional Python script that exploits CVE-2024-39713, an SSRF vulnerability in Rocket.Chat's Twilio webhook endpoint. The PoC sends a crafted JSON payload to the vulnerable endpoint, allowing an attacker to trigger SSRF by specifying an arbitrary target URL.
Nuclei Templates (1)
http.title:"rocket.chat"
title="rocket.chat"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N