Full Read SSRF in a PDF generation feature to read data from Internal domains
The Bug
The bug is a server-side request forgery vulnerability in a PDF generation feature that enabled me to read data from internal domains that are not publicly reachable
The Journey
I’ve been working on this application for three months now, and ...
eib.hashnode.dev6 min read