Collected research
Turning List-Unsubscribe into an SSRF/XSS Gadget
Treats the SMTP List-Unsubscribe header as attacker-controlled URL input in webmail applications. A JavaScript URI becomes stored XSS in Horde, while Nextcloud Mail's server-side unsubscribe request becomes blind SSRF; the article includes reproductions and validation guidance.
Record
- Researcher
- Lauritz Holtmann
- Published by
- (Web-)Insecurity Blog
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Lauritz Holtmann, first published at the original source. Preserved copies are kept so the citation survives its host.