More

    Critical server-side vulnerability in Microsoft Copilot Studio gives illegal access to internal infrastructure



    A critical vulnerability has been discovered in Microsoft’s Copilot Studio, posing significant risks to sensitive internal data. This flaw, identified as a server-side request forgery (SSRF), allows unauthorized access to internal infrastructure, potentially impacting multiple tenants.

    The flaw identified by Tenable’s Research Team is attributed to improper handling of redirect status codes in user-configurable actions, which allows attackers to manipulate HTTP requests.

    https://cdn.mos.cms.futurecdn.net/RWgUp9AVBugwCrdKoEv3zL-1200-80.png



    Source link
    benedict.collins@futurenet.com (Benedict Collins)

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img