PT-2025-51468 · WordPress · Fancy Product Designer
Muhammad Zeeshan
·
Publicado
2025-12-16
·
Atualizado
2025-12-17
·
CVE-2025-13231
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Fancy Product Designer versions prior to 6.4.9
Description
The software is susceptible to a Server-Side Request Forgery (SSRF) issue. This is caused by a time-of-check/time-of-use (TOCTOU) race condition within the 'url' parameter of the
fpd custom uplod file AJAX action. The validation process uses getimagesize() followed by file get contents() on the same URL, creating a timing gap that allows attackers to redirect requests to arbitrary internal or external URLs.Recommendations
Update The Fancy Product Designer plugin to version 6.4.9 or later.
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fancy Product Designer