OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/50670 | Exploit Third Party Advisory VDB Entry |
| https://www.openbmcs.com | Product |
| https://www.vulncheck.com/advisories/openbmcs-server-side-request-forgery-ssrf-via-phpqueryphp | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5694.php | Exploit Third Party Advisory |
Configurations
History
19 Dec 2025, 19:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/50670 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.openbmcs.com - Product | |
| References | () https://www.vulncheck.com/advisories/openbmcs-server-side-request-forgery-ssrf-via-phpqueryphp - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5694.php - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:openbmcs:openbmcs:2.4:*:*:*:*:*:*:* | |
| First Time |
Openbmcs openbmcs
Openbmcs |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
09 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 21:15
Updated : 2025-12-19 19:39
NVD link : CVE-2021-47703
Mitre link : CVE-2021-47703
CVE.ORG link : CVE-2021-47703
JSON object : View
Products Affected
openbmcs
- openbmcs
CWE
CWE-918
Server-Side Request Forgery (SSRF)
