PT-2022-25573 · Ndk Design · Ndkadvancedcustomizationfields
Dalii
·
Published
2022-11-22
·
Updated
2024-02-14
·
CVE-2022-40842
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ndk design NdkAdvancedCustomizationFields version 3.5.0
Description
The issue is related to Server-side request forgery (SSRF) via the rotateimg.php file. This allows for potential unauthorized access to internal resources.
Recommendations
For ndk design NdkAdvancedCustomizationFields version 3.5.0, consider restricting access to the rotateimg.php file as a temporary workaround until a patch is available.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ndkadvancedcustomizationfields