The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-08-29T17:15:35
Updated: 2024-08-03T00:32:09.262Z
Reserved: 2022-06-30T00:00:00
Link: CVE-2022-2267
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-08-29T18:15:09.310
Modified: 2022-09-01T06:45:16.130
Link: CVE-2022-2267
Redhat
No data.