Server Side Request Forgery in OpenBMCS 2.4 by OpenBMCS
CVE-2021-47703

6.9MEDIUM

Key Information:

Vendor

Open Bmcs

Status
Vendor
CVE Published:
9 December 2025

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2021-47703?

OpenBMCS version 2.4 is susceptible to an unauthenticated Server Side Request Forgery (SSRF) vulnerability. This flaw allows attackers to manipulate the application into making unauthorized HTTP requests to any specified external domain via the 'ip' parameter. Consequently, this can enable attackers to bypass firewall protections and perform network and service enumeration on the internal network, potentially leading to the hijacking of active sessions. It is critical for users to be aware of this vulnerability and take preventive measures to secure their systems.

Affected Version(s)

OpenBMCS 2.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

LiquidWorm as Gjoko Krstic of Zero Science Lab
.
CVE-2021-47703 : Server Side Request Forgery in OpenBMCS 2.4 by OpenBMCS