Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq5g-3m7v-mf66

Опубликовано: 30 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

EPSS

Процентиль: 26%
0.00092
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

EPSS

Процентиль: 26%
0.00092
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918