Loading HuntDB...

GHSA-fg6v-9r8w-4p8h

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.

Related CVEs

Key Information

GHSA ID
GHSA-fg6v-9r8w-4p8h
Published
April 10, 2024 3:30 PM
Last Modified
April 10, 2024 3:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.