What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0.
Explanation of Vulnerability in Simple Terms
WPO365 versions up to 40.0 contain a server-side request forgery vulnerability that allows authenticated users to make the site send HTTP requests to internal or external systems on the attacker's behalf. The vulnerability requires low-level authentication and affects the confidentiality and integrity of data accessible through those requests. Scope is changed, meaning the impact may extend beyond the vulnerable component itself.
What an attacker can do
Make the site send HTTP requests to internal systems or external URLs to read or modify data.
Potential impact on your site
Authenticated attackers can probe internal infrastructure, access private APIs, or trigger actions on external services.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities