4.9
CVSSv3

CVE-2022-28117

Published: 28/04/2022 Updated: 12/05/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote malicious users to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

naviwebs navigate cms 2.9.4

Exploits

Navigate CMS version 294 suffers from a server-side request forgery vulnerability ...

Github Repositories

Navigate CMS <= 2.9.4 - Server-Side Request Forgery (Authenticated)

CVE-2022-28117 Navigate CMS &lt;= 294 - Server-Side Request Forgery (Authenticated) Description A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v294 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter References nvdnistgov/vuln/detail/CVE-2022-28117 http

CVE 2022 28117 PoC python chỉnh sửa một chút Usage: python3 \poccve2022-28117py -x file:///etc/passwd -u [username] -p [password] 192168148140/navigate