Back to search
CVE-2021-24371
Published: Aug 2, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack.
| Vendor | Product | Versions |
|---|---|---|
Unknown | RSVPMaker | affected 8.7.3 - < 8.7.3 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now