← Zuruck zu CVEs
CVE-2022-28117
MEDIUM4.9
Beschreibung
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.
CVE Details
CVSS v3.1 Bewertung4.9
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht4/28/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
naviwebs:navigate_cms
Schwachen (CWE)
CWE-918
Referenzen
http://packetstormsecurity.com/files/167063/Navigate-CMS-2.9.4-Server-Side-Request-Forgery.html(cve@mitre.org)
https://www.youtube.com/watch?v=4kHW95CMfD0(cve@mitre.org)
http://packetstormsecurity.com/files/167063/Navigate-CMS-2.9.4-Server-Side-Request-Forgery.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.navigatecms.com/en/blog/development/navigate_cms_update_2_9_5(af854a3a-2127-422b-91ae-364da2661108)
https://www.youtube.com/watch?v=4kHW95CMfD0(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.