9.8
CVSSv3

CVE-2021-24472

Published: 02/08/2021 Updated: 27/08/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The OnAir2 WordPress theme prior to 3.9.9.2 and QT KenthaRadio WordPress plugin prior to 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qantumthemes kentharadio

qantumthemes onair2

Vendor Advisories

Check Point Reference: CPAI-2021-2095 Date Published: 8 Feb 2024 Severity: Critical ...