PT-2022-24620 · Unknown · Baijiacmsv4

Z3

·

Published

2022-09-20

·

Updated

2022-09-21

·

CVE-2022-38931

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions baijiacmsV4 version 4.1.4
Description A Server-Side Request Forgery (SSRF) issue exists in the fetch net file upload function, allowing remote attackers to force the application to make arbitrary requests by injecting arbitrary URLs into the url parameter.
Recommendations For baijiacmsV4 version 4.1.4, as a temporary workaround, consider restricting access to the fetch net file upload function until a patch is available. Avoid using the url parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-38931

Affected Products

Baijiacmsv4