CVE-2021-28941: SSRF
Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a request to the /scripts/magpiedebug.php or /scripts/magpiesimple.php page, it's possible to request any internal page if you use a https request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28941?
CVE-2021-28941 has a medium severity rating due to its potential for unauthorized access to internal pages.
How do I fix CVE-2021-28941?
To fix CVE-2021-28941, upgrade MagpieRSS to version 0.73 or later where the validation issue is resolved.
What is CVE-2021-28941?
CVE-2021-28941 is a vulnerability in MagpieRSS 0.72 related to a lack of validation on cURL commands that can expose internal pages.
Who is affected by CVE-2021-28941?
Users of MagpieRSS version 0.72 are affected by CVE-2021-28941 due to the vulnerable cURL implementation.
What are the implications of CVE-2021-28941?
CVE-2021-28941 may allow an attacker to exploit the application to gain access to sensitive internal resources.