cve/2022/CVE-2022-0591.md
2024-06-18 02:51:15 +02:00

912 B

CVE-2022-0591

Description

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

POC

Reference

Github