The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-05-16T14:30:50

Updated: 2022-05-16T14:30:50

Reserved: 2022-04-18T00:00:00


Link: CVE-2022-1386

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-16T15:15:09.310

Modified: 2024-03-14T19:58:30.707


Link: CVE-2022-1386

JSON object: View

cve-icon Redhat Information

No data.

CWE