The Booking Manager WordPress plugin... CVE-2023-1977

- AV AC AU C I A
发布: 2023-08-16
修订: 2023-11-07

The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息