CVE-2022-1398
External Media without Import <= 1.1.2 - Subscriber+ Blind SSRF
Record summary
CVE-2022-1398 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that medias added via URLs are external medias, which could allow any authenticated users, such as subscriber to perform blind SSRF attacks
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
External Media without Import | CVE List | 1.1.2 to ≤ 1.1.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMExternal Media without Import <=1.1.2 - Authenticated Blind Server-Side Request ForgeryCVSS 6.5
WordPress External Media without Import plugin through 1.1.2 is susceptible to authenticated blind server-side request forgery. The plugin has no authorization and does not ensure that media added via URLs are external media, which can allow any authenticated users, including subscribers, to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
Impact
Successful exploitation of this vulnerability could allow an attacker to bypass network restrictions, access internal resources, and potentially perform further attacks.
Remediation
Upgrade to External Media without Import plugin version 1.1.2 or later.
Source: ProjectDiscovery