Description
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-2566 Vulnerability (CVE-2015-2566)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1579)
Joomla! Core Security Bypass (1.7.0 - 3.9.22)
PHP Other Vulnerability (CVE-2007-1411)
WordPress Plugin WP Customer Reviews Cross-Site Scripting (3.4.2)