VDB
Sign up
LOW2.7

GHSA-hj6f-7hp7-xg69

Mautic vulnerable to SSRF via webhook function

Quick fix

GHSA-hj6f-7hp7-xg69 — mautic/core: upgrade to the fixed version with the command below.

composer require mautic/core:^4.4.17

Details

### Summary Users with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed

### Details When sending webhooks, the destination is not validated, causing SSRF.

### Impact Bypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/ for more potential impact.

### Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html for more information on SSRF and its fix

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mautic/core
Introduced in: 4.4.0Fixed in: 4.4.17
Fixcomposer require mautic/core:^4.4.17
Packagist/mautic/core
Introduced in: 5.0.0-alphaFixed in: 5.2.8
Fixcomposer require mautic/core:^5.2.8
Packagist/mautic/core
Introduced in: 6.0.0-alphaFixed in: 6.0.5
Fixcomposer require mautic/core:^6.0.5

References