The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-01T14:18:58.165Z

Updated: 2024-08-02T08:14:24.701Z

Reserved: 2023-10-31T12:53:17.769Z

Link: CVE-2023-5877

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-01T15:15:42.727

Modified: 2024-01-08T17:23:26.717

Link: CVE-2023-5877

cve-icon Redhat

No data.