What the vulnerability does
01Description
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
What the vulnerability does
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
Explanation of Vulnerability in Simple Terms
JetEngine versions up to 3.8.11 contain a server-side request forgery vulnerability that allows authenticated users to make the site send HTTP requests to internal or external systems on their behalf. The attacker needs low-level access and the vulnerability's impact is limited to information disclosure and minor modifications. The scope extends beyond the plugin itself.
What an attacker can do
Make the site send HTTP requests to internal systems or external servers to read data or perform actions.
Potential impact on your site
Authenticated attackers can probe your internal network, read sensitive data from internal services, or trigger actions on external systems.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities