Web Hack List

Collected research

Turning List-Unsubscribe into an SSRF/XSS Gadget

Treats the SMTP List-Unsubscribe header as attacker-controlled URL input in webmail applications. A JavaScript URI becomes stored XSS in Horde, while Nextcloud Mail's server-side unsubscribe request becomes blind SSRF; the article includes reproductions and validation guidance.

Record

Researcher
Lauritz Holtmann
Published by
(Web-)Insecurity Blog
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Lauritz Holtmann, first published at the original source. Preserved copies are kept so the citation survives its host.