CVE-2020-24149: SSRF
Published Jul 7, 2021
·Updated
Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcastfeed parameter in a secondlineimportinitialize action to the secondlinepodcastimport page.
Affected Software
1 affected component
SecondLine Podcast Importer Secondline Wordpress=1.1.4
Event History
Jul 7, 2021
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24149?
CVE-2020-24149 has a medium severity rating due to its potential for server-side request forgery.
2
How do I fix CVE-2020-24149?
To mitigate CVE-2020-24149, update the Podcast Importer SecondLine plugin to version 1.1.5 or later.
3
What software is affected by CVE-2020-24149?
CVE-2020-24149 affects the Podcast Importer SecondLine plugin version 1.1.4 for WordPress.
4
What type of vulnerability is CVE-2020-24149?
CVE-2020-24149 is classified as a server-side request forgery (SSRF) vulnerability.
5
How can CVE-2020-24149 impact my website?
Exploitation of CVE-2020-24149 could allow an attacker to send unauthorized requests from the server, potentially exposing sensitive information.