Unauthenticated SSRF in `/target/api/request` allows any anonymous user to bypass documentation authentication and read protected/private docs sites cross-tenant
1 week ago · 3
pentestinghere/null_x07 hiking Rank: Contributor gavel Moderator of PentestingHere
Cybersecurity student at Ain Shams University with a passion for web application security and bug bounty hunting. I've successfully reported accepted security vulnerabilities through bug bounty programs and continue to improve my skills in web application and API security. Always learning, building, and connecting with the cybersecurity community.
calendar_month Joined Aug 2026
75 reputation to Hunter
1 week ago · favorite 3