PT-2024-12475 · Beaver Builder+2 · Beaver Builder+3
Rafie Muhammad
·
Published
2024-03-27
·
Updated
2024-03-28
·
CVE-2023-34370
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates versions 3.2.4 and earlier
Brainstorm Force Premium Starter Templates versions 3.2.4 and earlier
Description
A Server-Side Request Forgery (SSRF) issue affects the software, allowing unauthorized access to internal resources. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations
For Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates versions 3.2.4 and earlier, update to a version later than 3.2.4.
For Brainstorm Force Premium Starter Templates versions 3.2.4 and earlier, update to a version later than 3.2.4.
As a temporary workaround, consider restricting access to internal resources to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Beaver Builder
Brainstorm Force Premium Starter Templates
Brainstorm Force Starter Templates
Elementor