ZeroHour

CVE-2022-38931

PoC
CVSS 3.1
8.8 high
EPSS
1%p66
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter.

Vendors
baijiacms project
Products
baijiacms
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.