CVE-2013-2199Server-Side Request Forgery in Wordpress

7 documents5 sources
Severity
4.3MEDIUMNVD
OSV6.4
EPSS
0.8%
top 25.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8
Latest updateMay 17

Description

The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 3.5.2+dfsg-1 (bookworm)
Debianwordpress/wordpress< 3.5.2+dfsg-1+3
NVDwordpress/wordpress3.5.1+74

🔴Vulnerability Details

2
GHSA
GHSA-7372-64f4-g53c: The HTTP API in WordPress before 32022-05-17
OSV
CVE-2013-2199: The HTTP API in WordPress before 32013-07-08

📋Vendor Advisories

1
Debian
CVE-2013-2199: wordpress - The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requ...2013

💬Community

3
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [epel-all]2013-06-22
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version [fedora-all]2013-06-22
Bugzilla
CVE-2013-2199 CVE-2013-2200 CVE-2013-2201 CVE-2013-2202 CVE-2013-2203 CVE-2013-2204 CVE-2013-2205 wordpress: Multiple security flaws to be corrected within upstream 3.5.2 version2013-06-21