Tag
high
advisory
Ech0 Unauthenticated Server-Side Request Forgery Vulnerability
2 rules 1 TTP 1 IOCEch0 is vulnerable to Server-Side Request Forgery (SSRF) due to an unauthenticated API endpoint (`/api/website/title`) that fetches website titles from user-controlled URLs, lacking proper validation and TLS verification, allowing attackers to access internal resources and potentially cause denial of service.
ssrf
ech0
web-application
2r
1t
1i
high
advisory
Ech0 Server-Side Request Forgery (SSRF) Vulnerability
2 rules 1 TTP 2 IOCsEch0 is vulnerable to Server-Side Request Forgery (SSRF) via the `fetchPeerConnectInfo` function, which uses `httpUtil.SendRequest` without SSRF protection, allowing authenticated users to make the server request arbitrary URLs, including internal/cloud metadata endpoints.
ech0
ssrf
github
2r
1t
2i