PT-2022-16047 · WordPress · Post Smtp Mailer/Email Log

Raad Haddad

·

Published

2022-09-26

·

Updated

2022-10-05

·

CVE-2022-2352

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Post SMTP Mailer/Email Log WordPress plugin versions prior to 2.1.7
Description The issue concerns a lack of proper authorization in some AJAX actions within the plugin, potentially allowing high-privilege users, such as administrators, to perform blind Server-Side Request Forgery (SSRF) attacks on multisite installations. SSRF is a type of attack where an attacker can trick a server into making requests to internal or external systems, potentially leading to unauthorized access or data exposure.
Recommendations For versions prior to 2.1.7, update to version 2.1.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions in question or limiting the privileges of users who can access these actions until the update can be applied.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2352

Affected Products

Post Smtp Mailer/Email Log