9.1
CVSSv3

CVE-2022-41477

Published: 14/10/2022 Updated: 20/10/2022
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9

Vulnerability Summary

A security issue exists in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote malicious users to inject payloads via theme parameters to read files across directories.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webidsupport webid

Github Repositories

CVE-2022-41477 A security issue was discovered in WeBid &lt;=122 A Server-Side Request Forgery (SSRF) vulnerability in the admin/themephp file allows remote attackers to inject payloads via theme parameters to read files across directories authentication complexity vector not available not available not available confidentiality integrity availability