low

AWS AppFlow WooCommerce SSRF

Published Mon, Nov 6th, 2023
Platforms

Summary

The AppFlow WooCommerce connector allowed specification of a full URL. The connector included details of response content when the URL offered an unexpected response. This means you could make arbitrary GET requests to any URL from the WooCommerce connector, and view the response content. The response in the error was truncated to 500 characters.

Affected Services

AppFlow

Remediation

None required

Tracked CVEs

No tracked CVEs

References

Entry Status
Finalized
Disclosure Date
Wed, Jun 21st, 2023
Exploitablity Period
-
Known ITW Exploitation
-
Detection Methods
-
Piercing Index Rating
-
Discovered by
Ronin