Description
Server-Side Request Forgery (SSRF) vulnerability allows an attacker to perform local and/or remote network requests while impersonating the target server. Using this vulnerability, Acunetix was able to access the target's localhost service.
Remediation
Properly sanitize user input.
References
Related Vulnerabilities
WordPress Plugin PhonePe Payment Solutions Server-Side Request Forgery (1.0.15)
SAP BO BIP SSRF (CVE-2020-6308)
WordPress Plugin Mapplic-Custom Interactive Map Server-Side Request Forgery (6.1)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.11)
WordPress Plugin Craw Data Server-Side Request Forgery (1.0.0)