Vulnerabilities > CVE-2021-28941 - Server-Side Request Forgery (SSRF) vulnerability in Magpierss Project Magpierss 0.72

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
magpierss-project
CWE-918

Summary

Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpie_debug.php or /scripts/magpie_simple.php page, it's possible to request any internal page if you use a https request.

Vulnerable Configurations

Part Description Count
Application
Magpierss_Project
1

Common Weakness Enumeration (CWE)