Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-24148. PoCs published by dwisiswant0. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a valid proof-of-concept for CVE-2020-24148, an SSRF vulnerability in the Import XML and RSS Feeds WordPress plugin. The exploit leverages the `data` parameter in the `moove_read_xml` action to perform server-side requests to arbitrary URLs.
Description
Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.
Exploits (1)
This repository contains a valid proof-of-concept for CVE-2020-24148, an SSRF vulnerability in the Import XML and RSS Feeds WordPress plugin. The exploit leverages the `data` parameter in the `moove_read_xml` action to perform server-side requests to arbitrary URLs.
Nuclei Templates (1)
http.html:"import-xml-feed"
body="import-xml-feed"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H