PT-2022-17282 · Ntt Resonant Incorporated · Ntt Resonant Incorporated Goo Blog App Web Application

Abhijeet Singh

+1

·

Published

2022-03-29

·

Updated

2022-04-04

·

CVE-2022-25420

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NTT Resonant Incorporated goo blog App Web Application version 1.0
Description The issue allows attackers to execute arbitrary code via a crafted HTTP request, specifically through CLRF injection. This enables attackers to potentially gain control over the system by injecting malicious commands.
Recommendations For NTT Resonant Incorporated goo blog App Web Application version 1.0, consider restricting access to the application until a fix is available, and avoid using the application for sensitive operations. As a temporary workaround, consider implementing additional validation and sanitization for HTTP requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25420

Affected Products

Ntt Resonant Incorporated Goo Blog App Web Application