T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/inspect.js:59- Finding
Unrestricted Navigation to Page-Controlled URLs Enables Browser-Based SSRF
- Content
View full analysis
{ const text = (el.innerText || el.textContent || '').replace(/\s+/g, ' ').trim(); let href = el.getAttribute('href') || ''; // For SPA hash routes, resolve full URL if (href && !href.startsWith('http')) { href = window.location.origin + window.location.pathname + href; } const key = text + '||' + href; if (text.length > 1 && text.length < 50 && !seen.has(key)) { seen.add(key); results.push({ name: text, url: href || window.location.href }); } }); ``` ```javascript try { await page.goto(p.url, { waitUntil: 'networkidle', timeout: 20000 }).catch(() => {}); await sleep(config.pageWaitMs || 2500); ``` ### Technical Analysis The page-discovery routine extracts links from the audited application's DOM and accepts absolute URLs without validating their origin, protocol, hostname, or resolved IP address. Every discovered URL is subsequently supplied to Playwright's `page.goto()`. Because the audited application controls the DOM from which links are collected, it can direct the browser to resources outside the configured application's origin. Potential destinations include loopback addresses, private network services, link-local addresses, administrative interfaces, and cloud instance metadata endpoints. The code also does not distinguish ordinary navigation links from GET endpoints that perform state-changing actions. The inspection process captures screenshots and extracts visible page content after navigation. Consequently, content returned by an internally reachable destinati ...[truncated 1610 chars]- Remediation
View remediation
