SYM_JSTS_0038 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki

Server-Side Request Forgery (SSRF)

Property Value
Language javascript
Severity medium
CWE CWE-918: Server-Side Request Forgery (SSRF)
OWASP A10:2021 - Server-Side Request Forgery (SSRF)
Confidence Level Low
Impact Level Medium
Likelihood Level Medium

Description

If unverified user data can reach the phantom methods it can result in Server-Side Request Forgery vulnerabilities