ZeroHour

CVE-2022-28117

PoC ×2
CVSS 3.1
4.9 medium
EPSS
23%p98
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

Vendors
naviwebs
Products
navigate cms
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.