What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.2.
Explanation of Vulnerability in Simple Terms
Solace Extra versions up to 1.3.2 contain a server-side request forgery vulnerability that allows high-privilege users to make the site send requests to internal or external systems. The attacker must have administrative access and the scope extends beyond the vulnerable component. Low-level confidentiality and integrity impacts are possible.
What an attacker can do
Make the site send HTTP requests to internal systems or external servers on the attacker's behalf.
Potential impact on your site
An admin account could be compromised to probe your internal network or exfiltrate data via forced requests.
Conditions required to exploit
Attacker must have high-level administrative privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities