PT-2022-16881 · C1 Cms · C1 Cms
Jarlob
+1
·
Published
2022-03-28
·
Updated
2022-04-05
·
CVE-2022-24789
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
C1 CMS versions prior to 6.12
Description
The issue allows an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. This can also lead to truncating arbitrary files to zero size, effectively deleting them, which can cause denial of service (DoS) or alter application logic. An authenticated user may unknowingly perform these actions by visiting a specially crafted site.
Recommendations
For versions prior to 6.12, update to C1 CMS version 6.12 to resolve the issue.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
C1 Cms