Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j66q-h2jj-3578

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

EPSS

Процентиль: 100%
0.8982
Высокий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

EPSS

Процентиль: 100%
0.8982
Высокий

Дефекты

CWE-918