CSSTidy - Server-Side Request Forgery
highThe module cerdic/csstidy, which is used in several plugins, is vulnerable to Server-Side Request Forgery due to the inclusion of test code that does not verify a user-provided URL. This can allow unauthenticated attackers to to make web requests to arbitrary locations originating from the web application which can be...
- CVSS:
- 8.3
- Affected:
- up to 1.2.2.
- Fix:
- No patched version reported
- Disclosed:
- Mar 3, 2023