PT-2021-17995 · Magpierss · Magpierss
Bl4Ckh4Ck5
·
Published
2021-04-02
·
Updated
2021-04-08
·
CVE-2021-28941
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
MagpieRSS version 0.72
Description:
The issue arises from a lack of validation on a curl command in the /extlib/Snoopy.class.inc file. This allows an attacker to request any internal page when sending a request to the /scripts/magpie debug.php or /scripts/magpie simple.php page using a https request.
Recommendations:
For MagpieRSS version 0.72, consider disabling the curl command functionality in the /extlib/Snoopy.class.inc file until a patch is available. Restrict access to the /scripts/magpie debug.php and /scripts/magpie simple.php pages to minimize the risk of exploitation. Avoid using the https request method in these pages until the issue is resolved.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magpierss