Server Side Request Forgery (SSRF) via Analytics Report
- Navigate to https://hackerone.com/organizations/ORG/analytics/reports
- Create new report.
- Choose some filters.
- Click on “Apply”. [intercept the request in this step] in any “template” field; inject any HTML payload.
- Now inject an <Iframe> to read internal files as shown in the above POC.
Inject something like
169.254.169.254/latest/meta-data/hostname
169.254.169.254/latest/meta-data/