Burp Suite User Forum

Create new post

SSRF with filter bypass via open redirection vulnerability

Momo | Last updated: Aug 18, 2021 06:22PM UTC

Hello I do not understand why I can't access the admin panel through such a request : GET /product/nextProduct?currentProductId=2&path=path=http://192.168.0.12:8080/admin/delete?username=carlos Why do we have to do it via the check stock request ?

Michelle, PortSwigger Agent | Last updated: Aug 19, 2021 09:22AM UTC

Hi Thanks for your message. If you take a look through the 'Bypassing SSRF filters via open redirection' section of the resources on this page, https://portswigger.net/web-security/ssrf, this might help to explain the background to this lab in a bit more detail. I hope this helps :-)

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.