CVE Database
/

CVE-2021-24371

Back to search

CVE-2021-24371

Published: Aug 2, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack.

VendorProductVersions

Unknown

RSVPMaker

affected
8.7.3 - < 8.7.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now