PT-2022-16047 · WordPress · Post Smtp Mailer/Email Log
Raad Haddad
·
Published
2022-09-26
·
Updated
2022-10-05
·
CVE-2022-2352
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Post SMTP Mailer/Email Log WordPress plugin versions prior to 2.1.7
Description
The issue concerns a lack of proper authorization in some AJAX actions within the plugin, potentially allowing high-privilege users, such as administrators, to perform blind Server-Side Request Forgery (SSRF) attacks on multisite installations. SSRF is a type of attack where an attacker can trick a server into making requests to internal or external systems, potentially leading to unauthorized access or data exposure.
Recommendations
For versions prior to 2.1.7, update to version 2.1.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions in question or limiting the privileges of users who can access these actions until the update can be applied.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Post Smtp Mailer/Email Log