S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-27670 Scanner

CVE-2021-27670 scanner - Server-Side Request Forgery vulnerability in Appspace

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-27670
9.8
CVSS

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Appspace is a widely used platform for digital signage and space management, providing solutions for workplace experience applications such as room booking, digital signage, and corporate communications. It is designed for organizations looking to manage their physical and digital workspaces effectively. The platform facilitates the integration of digital content and space management tools into a single, easy-to-use interface, enhancing workplace efficiency and communication. Appspace's adoption spans various industries, including corporate offices, educational institutions, and healthcare facilities, making it an essential tool for modern workspace management.

The SSRF vulnerability is present in the api/v1/core/proxy/jsonprequest endpoint of Appspace 6.2.4, where the application fails to properly sanitize the url parameter. This oversight allows attackers to send crafted requests that can cause the application to fetch data from or interact with arbitrary URLs specified by the attacker. Such behavior can be exploited to access internal network resources, bypass firewall protections, and conduct port scanning activities, posing a significant risk to the security posture of the affected organization.

Exploiting this SSRF vulnerability could lead to severe consequences, including unauthorized access to internal network services, sensitive data exposure, and potentially facilitating remote code execution. The ability to send requests to internal resources can compromise the confidentiality and integrity of the organization's data and network infrastructure, leading to data breaches, service disruptions, and a loss of trust among users and clients.

S4E platform offers comprehensive cybersecurity solutions that empower organizations to detect, analyze, and remediate vulnerabilities such as CVE-2021-27670. By joining our platform, you gain access to advanced scanning technologies, real-time threat intelligence, and expert guidance to enhance your security posture. Our service enables proactive vulnerability management, ensuring your digital assets are safeguarded against emerging threats and maintaining the resilience of your cyber defenses.

 

References

Solution Advice
  1. Immediately upgrade to the latest version of Appspace that addresses the SSRF vulnerability or apply available security patches.
  2. Implement strict input validation and sanitization for all user-supplied data, especially URL parameters, to prevent malicious inputs.
  3. Employ network segmentation and firewall rules to restrict access from the application server to internal network resources.
  4. Conduct regular security assessments and penetration testing to identify and mitigate vulnerabilities in your digital environment.
  5. Educate your development and IT teams on the risks associated with SSRF and the importance of secure coding practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.