3 ms·
Unpatched Powerful SSRF in Exchange OWA – Getting Response Through Attachments
- freedude 3y agoTLDR; ZDI-CAN-22101 – CreateAttachmentFromURI Server-Side Request Forgery To sum up, the following attack scenario is possible: • The attacker authenticates to OWA. • The attacker creates a new draft message. • The attacker invokes CreateAttachmentFromUri, triggering the SSRF. • The response of the SSRF gets added to the mail message as an attachment. • The attacker downloads the attachment and retrieves the response content.