Vulnerabilities > CVE-2020-24149 - Server-Side Request Forgery (SSRF) vulnerability in Secondline Podcast Importer Secondline 1.1.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
secondline
CWE-918

Summary

Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.

Vulnerable Configurations

Part Description Count
Application
Secondline
1

Common Weakness Enumeration (CWE)