ZeroHour

CVE-2022-40296

CVSS 3.1
9.8 critical
EPSS
<1%p50
Published
()
Modified
Description

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

Vendors
phppointofsale
Products
php point of sale
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.