PT-2022-25573 · Ndk Design · Ndkadvancedcustomizationfields

Dalii

·

Published

2022-11-22

·

Updated

2024-02-14

·

CVE-2022-40842

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ndk design NdkAdvancedCustomizationFields version 3.5.0
Description The issue is related to Server-side request forgery (SSRF) via the rotateimg.php file. This allows for potential unauthorized access to internal resources.
Recommendations For ndk design NdkAdvancedCustomizationFields version 3.5.0, consider restricting access to the rotateimg.php file as a temporary workaround until a patch is available.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-40842

Affected Products

Ndkadvancedcustomizationfields