What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.
Explanation of Vulnerability in Simple Terms
Instant Images versions up to 5.1.0.2 contain a server-side request forgery vulnerability that allows high-privilege users to make the site send requests to internal or external systems on their behalf. An attacker with administrative access can exploit this to access restricted resources, retrieve sensitive data, or interact with internal services. The vulnerability requires high-level privileges and does not require user interaction.
What an attacker can do
Make the site send HTTP requests to internal or external systems to access restricted resources or retrieve sensitive data.
Potential impact on your site
An admin account compromise could allow attackers to probe internal networks, access cloud metadata, or exfiltrate data via the site.
Conditions required to exploit
Attacker must have high-level administrative privileges on the site.
Key dates
External resources
Related vulnerabilities