PT-2025-35709 · Webhook · Webhook
Asesidaa
+3
·
Published
2025-09-03
·
Updated
2025-09-03
·
CVE-2025-9821
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
versions not specified
Description
Users with webhook permissions can conduct Server-Side Request Forgery (SSRF) via webhooks. If they have permission to view the webhook logs, the partial request response is also disclosed. This allows bypassing firewalls to interact with internal services.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webhook