rachelos WeRSS we-mp-rss Webhook mps.py do_job server-side request forgery
Vulnerability Description
A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function do_job of the file /rachelos/we-mp-rss/blob/main/jobs/mps.py of the component Webhook Module. Executing manipulation of the argument web_hook_url can lead to server-side request forgery. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13174
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- din4 (VulDB User)
Affected Vendor
rachelos
View all reports →