CVE-2012-10018

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.
Configurations

No configuration.

History

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) Los complementos Mapplic y Mapplic Lite para WordPress son vulnerables a Server-Side Request Forgery en las versiones 6.1 y 1.0, respectivamente. Esto permite a los atacantes falsificar solicitudes provenientes del servidor de un sitio vulnerable y, en Ășltima instancia, realizar un ataque XSS si se solicita un archivo SVG.

16 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 07:15

Updated : 2024-10-16 16:38


NVD link : CVE-2012-10018

Mitre link : CVE-2012-10018

CVE.ORG link : CVE-2012-10018


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)