9.8

CVE-2019-11565

Exploit

Print My Blog <= 1.6.6 - Server-Side Request Forgery

Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
Mögliche Gegenmaßnahme
Print My Blog – Print, PDF, & eBook Converter WordPress Plugin: Update to version 1.6.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Print My Blog ProjectPrint My Blog SwPlatformwordpress Version < 1.6.7
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Print My Blog – Print, PDF, & eBook Converter WordPress Plugin
Version *-1.6.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.82% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

http://dumpco.re/bugs/wp-plugin-print-my-blog-ssrf
Third Party Advisory
Exploit
Issue Tracking
https://github.com/mnelson4/printmyblog/commit/8584a2839a541eb29fca64252e388c827af3ec21
Patch
Third Party Advisory
https://plugins.trac.wordpress.org/changeset?old_path=%2Fprint-my-blog%2Ftrunk&old=2075667&new_path=%2Fprint-my-blog%2Ftrunk&new=2075667
Patch
Third Party Advisory
https://wordpress.org/plugins/print-my-blog/#developers
Third Party Advisory
Release Notes
https://wpvulndb.com/vulnerabilities/9263
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/23fbb011-cf60-4c75-ac68-b5d0dfa3c356
Third Party Advisory