Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24472

Опубликовано: 02 авг. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Высокий

Описание

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:qantumthemes:kentharadio:*:*:*:*:*:wordpress:*:*
Версия до 2.0.2 (исключая)
cpe:2.3:a:qantumthemes:onair2:*:*:*:*:*:wordpress:*:*
Версия до 3.9.9.2 (исключая)

EPSS

Процентиль: 100%
0.8982
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-918

Связанные уязвимости

github
больше 3 лет назад

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

EPSS

Процентиль: 100%
0.8982
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-918