HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2024-13924
发布日期2025-03-08T12:21:32.041Z
更新日期2025-03-11T16:06:54.913Z
状态PUBLISHED
受影响的供应商fancywp
受影响的产品Starter Templates by FancyWP
描述The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the 'http_request_host_is_external' filter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

参考链接:

Image Additional Image