CVE-2023-1977
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
16/08/2023
Last modified:
07/11/2023
Description
The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:oplugins:booking_manager:*:*:*:*:*:wordpress:*:* | 2.0.29 (excluding) |
To consult the complete list of CPE names with products and versions, see this page