The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

SSRF with filter bypass via open redirection vulnerability

Momo | Last updated: Aug 18, 2021 06:22PM UTC

Hello I do not understand why I can't access the admin panel through such a request : GET /product/nextProduct?currentProductId=2&path=path=http://192.168.0.12:8080/admin/delete?username=carlos Why do we have to do it via the check stock request ?

Michelle, PortSwigger Agent | Last updated: Aug 19, 2021 09:22AM UTC