SSRF Vulnerability in Glastopf 3.1.3-dev with Intentional Behavior

SSRF Vulnerability in Glastopf 3.1.3-dev with Intentional Behavior

CVE-2018-10220 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote File Inclusion emulation

Learn more about our Web App Pen Testing.