PT-2022-25573 · Ndk Design · Ndkadvancedcustomizationfields

·

CVE-2022-40842

·

Published

2022-11-22

·

Updated

2024-02-14

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ndk design NdkAdvancedCustomizationFields version 3.5.0
Description The issue is related to Server-side request forgery (SSRF) via the rotateimg.php file. This allows for potential unauthorized access to internal resources.
Recommendations For ndk design NdkAdvancedCustomizationFields version 3.5.0, consider restricting access to the rotateimg.php file as a temporary workaround until a patch is available.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-40842

Affected Products

Ndkadvancedcustomizationfields