PT-2022-16881 · C1 Cms · C1 Cms

Jarlob

+1

·

Published

2022-03-28

·

Updated

2022-04-05

·

CVE-2022-24789

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions C1 CMS versions prior to 6.12
Description The issue allows an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. This can also lead to truncating arbitrary files to zero size, effectively deleting them, which can cause denial of service (DoS) or alter application logic. An authenticated user may unknowingly perform these actions by visiting a specially crafted site.
Recommendations For versions prior to 6.12, update to C1 CMS version 6.12 to resolve the issue.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24789
GHSA-8PP6-8X4Q-C5MX
GHSA-J9C2-GR6M-PP45

Affected Products

C1 Cms