TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-40296

CRITICAL
9.8

Beschreibung

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht10/31/2022
Zuletzt geandert5/6/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

phppointofsale:php_point_of_sale

Schwachen (CWE)

CWE-918CWE-918CWE-918

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.