CVE-2020-13484
24.06.2020, 15:15
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
Vendor | Product | Version |
---|---|---|
bitrix24 | bitrix24 | 𝑥 ≤ 20.0.975 |
𝑥
= Vulnerable software versions