PoC Index

CVE-2021-24472

CRITICAL 9.8EPSS 56.6%

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
56.61% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-918
Published
2021-08-02
Updated
2024-08-03

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related