Server-Side Request Forgery Vulnerability in Oshine Modules by NotFound
CVE-2024-44055

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
31 January 2025

Summary

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Oshine Modules by NotFound. This flaw allows an attacker to send crafted requests from the server, potentially exposing sensitive information and compromising the server's security. By exploiting this vulnerability, unauthorized users could manipulate requests, leading to unauthorized access to internal resources. It is crucial for developers and website administrators using Oshine Modules to update to the latest versions and implement additional security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Oshine Modules < 3.3.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.