PT-2024-23382 · Brave · Brave Popup Builder

Majed Refaea

·

Published

2024-03-29

·

Updated

2024-07-18

·

CVE-2024-30453

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Brave Popup Builder versions 0.6.5 and earlier
Description A Server-Side Request Forgery (SSRF) issue affects the Brave Popup Builder, allowing unauthorized access to internal resources. No information is provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For versions 0.6.5 and earlier, update to a version later than 0.6.5 to resolve the issue. As a temporary workaround, consider restricting access to internal resources to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2024-30453
BIT-WORDPRESS-MULTISITE-2024-30453
CVE-2024-30453

Affected Products

Brave Popup Builder