Vulnerability CVE-2022-28997


Published: 2022-05-23

Description:
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

 References:
https://i.imgur.com/pzWjkXI.png
https://i.imgur.com/BwWTfYU.png
https://i.imgur.com/xxjxnGk.png
https://i.imgur.com/S1F7MaJ.png
https://packetstormsecurity.com/files/166613/CSZCMS-1.3.0-SSRF-LFI-Remote-Code-Execution.html

Copyright 2024, cxsecurity.com

 

Back to Top