Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2287

Опубликовано: 30 мая 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:themeisle:orbitfox:*:*:*:*:*:wordpress:*:*
Версия до 2.10.24 (исключая)

EPSS

Процентиль: 26%
0.00092
Низкий

4.3 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 4.3
github
больше 2 лет назад

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

EPSS

Процентиль: 26%
0.00092
Низкий

4.3 Medium

CVSS3

Дефекты