4. Create a nc listener nc -lp 5000 5. Run python3 dodyssey.py 6. You will get a hit on your nc showing we have successfully proceded to send a server side request 7. dodyssey.py will show error since there is no img file on the url, but we are able to do SSRF "> ,4.,Create,a,nc,listener,nc -lp,5000,5.,Run,python3,dodyssey.py,6.,You,will,get,a,hit,on,your,nc showing,we,have,successfully,proceded,to,send,a,server,side,request,7. dodyssey.py,will,show,error,since,there,is,no,img,file,on,the,url,,but we,are,able,to,do,SSRF "> SecuritySpace - CVE-2020-28463
 
 
 Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-28463
Description:All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of reportlab 2. Go to demos -> odyssey -> dodyssey 3. In the text file odyssey.txt that needs to be converted to pdf inject 4. Create a nc listener nc -lp 5000 5. Run python3 dodyssey.py 6. You will get a hit on your nc showing we have successfully proceded to send a server side request 7. dodyssey.py will show error since there is no img file on the url, but we are able to do SSRF
Test IDs: 1.3.6.1.4.1.25623.1.0.854044   1.3.6.1.4.1.25623.1.0.819188   1.3.6.1.4.1.25623.1.1.10.2021.0521   1.3.6.1.4.1.25623.1.1.1.2.2023.3590   1.3.6.1.4.1.25623.1.0.854065   1.3.6.1.4.1.25623.1.0.819086  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-28463
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YZQSFCID67K6BTC655EQY6MNOF35QI44/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMUJA5GZTPQ5WRYUCCK2GEZM4W43N7HH/
https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145
https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145
https://www.reportlab.com/docs/reportlab-userguide.pdf
https://www.reportlab.com/docs/reportlab-userguide.pdf
https://lists.debian.org/debian-lts-announce/2023/09/msg00037.html




© 1998-2025 E-Soft Inc. All rights reserved.