PT-2022-25983 · Unknown · Bp Better Messages

·

CVE-2022-41609

·

Published

2022-11-18

·

Updated

2022-11-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Better Messages plugin version 1.9.10.68
Description The issue is related to an Authenticated Server-Side Request Forgery (SSRF) vulnerability. This means that an attacker could potentially forge requests to internal or external services, but only if they have authenticated access to the system as a subscriber or higher.
Recommendations For Better Messages plugin version 1.9.10.68, update to a newer version that contains a fix for this issue, if available. As a temporary workaround, consider restricting access to sensitive internal services to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-41609

Affected Products

Bp Better Messages