Lucene search

K
cveWPScanCVE-2022-3247
HistoryOct 25, 2022 - 5:15 p.m.

CVE-2022-3247

2022-10-2517:15:56
CWE-918
WPScan
web.nvd.nist.gov
40
4
cve-2022-3247
blog2social
social media
auto post
scheduler
wordpress
ssrf
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

24.8%

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

Affected configurations

Nvd
Vulners
Node
adenionblog2socialRange<6.9.10wordpress
VendorProductVersionCPE
adenionblog2social*cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Blog2Social: Social Media Auto Post & Scheduler",
    "versions": [
      {
        "version": "6.9.10",
        "status": "affected",
        "lessThan": "6.9.10",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

24.8%