PT-2023-22604 · WordPress · Dropbox Folder Share

Alex Thomas

·

Published

2023-09-16

·

Updated

2023-09-20

·

CVE-2023-3025

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dropbox Folder Share plugin for WordPress versions up to, and including, 1.9.7
Description The issue allows unauthenticated attackers to make web requests to arbitrary locations originating from the web application via the link parameter. This can be used to query and modify information from internal services, exploiting Server-Side Request Forgery.
Recommendations For versions up to, and including, 1.9.7, consider disabling the link parameter until a patch is available to prevent exploitation. Restrict access to internal services to minimize the risk of information modification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-3025

Affected Products

Dropbox Folder Share