CVE-2024-51665
MEDIUMNoor alam Magical Addons For Elementor <1.2.1 - SSRF
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-51665. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This PoC demonstrates an authenticated SSRF vulnerability in Magical Addons For Elementor <= 1.2.1, allowing attackers with Subscriber-level access to make arbitrary web requests from the server. The provided HTTP request shows exploitation via the `magical_addon_import_template` action with a malicious `parent_site` parameter.
Description
Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through <= 1.2.1.
Exploits (1)
This PoC demonstrates an authenticated SSRF vulnerability in Magical Addons For Elementor <= 1.2.1, allowing attackers with Subscriber-level access to make arbitrary web requests from the server. The provided HTTP request shows exploitation via the `magical_addon_import_template` action with a malicious `parent_site` parameter.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N