Title: PHProxy Server-Side Request Forgery (SSRF) vulnerability
Advisory ID: CVE-2025-52362
Type: Remote
Impact: Information Disclosure, Bypass of server-side network controls
Release Date: 2025/7/20
PHProxy is a web HTTP proxy written in PHP. It is designed to bypass proxy restrictions through a web interface very similar to the popular CGIProxy.
Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can be bypassed, allowing a remote, unauthenticated attacker to submit a specially crafted URL.
PHProxy - https://github.com/PHProxy/phproxy
PHProxy - v1.1.1 and prior
https://f0rget.me/2025/06/13/phproxy-server-side-request-forgery-ssrf-vulnerability/
Shule - [email protected]
[1] https://github.com/PHProxy/phproxy
[2] https://f0rget.me/2025/06/13/phproxy-server-side-request-forgery-ssrf-vulnerability/
Shule
Web: https://f0rget.me/
e-mail: [email protected]