Vulnerability Description
Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/4d72d300-92d6-4e3c-93d8-52fe47396ae0
- https://huntr.com/bounties/4d72d300-92d6-4e3c-93d8-52fe47396ae0
FAQ
What is CVE-2024-3448?
CVE-2024-3448 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery ...
How severe is CVE-2024-3448?
CVE-2024-3448 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-3448?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.