Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle
xbow.com | vulnerability | Critical | #vulnerability-research | #ssrf | #exfiltration | #file-read | #titiler | #geospatial
Summary
Details how XBOW escalated a blind SSRF in TiTiler into a full arbitrary file read via byte-by-byte exfiltration in a 48-step chain, from OpenAPI recon to the final oracle.
- CVSS
- 9.3
- Published
- Collected
Skip to content