CVE-2024-0337
MEDIUM NUCLEITravelpayouts WordPress plugin < 1.1.17 - Unauthenticated Open Redirect
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-0337. PoCs published by halilkirazkaya. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains functional proof-of-concept exploits for multiple CVEs, including remote file inclusion, path traversal, arbitrary file deletion, and unauthorized metadata updates. Each PoC includes HTTP requests demonstrating the vulnerability.
Description
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Exploits (1)
This repository contains functional proof-of-concept exploits for multiple CVEs, including remote file inclusion, path traversal, arbitrary file deletion, and unauthorized metadata updates. Each PoC includes HTTP requests demonstrating the vulnerability.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N