What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.
Explanation of Vulnerability in Simple Terms
Church Admin versions up to 3.7.56 contain a server-side request forgery vulnerability that allows high-privilege users to make the site send HTTP requests to internal or external systems on their behalf. The attacker must have administrative access and the scope of impact extends beyond the vulnerable component. This could enable reconnaissance of internal infrastructure or interaction with restricted services.
What an attacker can do
Make the site send HTTP requests to internal or external systems without authorization.
Potential impact on your site
An admin account could be compromised to probe your internal network or interact with restricted external services.
Conditions required to exploit
Attacker must have high-level administrative privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities