PT-2022-25894 · Unknown · Clippercms

Published

2022-10-13

·

Updated

2025-05-15

·

CVE-2022-41497

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClipperCMS version 1.3.3
Description A Server-Side Request Forgery (SSRF) issue was discovered, which can be exploited via the pkg url parameter at the "/manager/index.php" API endpoint.
Recommendations For ClipperCMS version 1.3.3, avoid using the pkg url parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-41497

Affected Products

Clippercms