CVE-2022-28090: SSRF
Published May 4, 2022
·Updated
Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetchurl.do?url=.
Affected Software
1 affected component
Ujcms Jspxcms=10.2.0
Event History
May 4, 2022
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28090?
CVE-2022-28090 is classified as a critical vulnerability due to its potential for Server-Side Request Forgery (SSRF) attacks.
2
How do I fix CVE-2022-28090?
To fix CVE-2022-28090, upgrade Jspxcms to version 10.2.1 or later, which addresses this vulnerability.
3
What type of vulnerability is CVE-2022-28090?
CVE-2022-28090 is a Server-Side Request Forgery (SSRF) vulnerability.
4
What are the potential impacts of CVE-2022-28090?
Exploitation of CVE-2022-28090 may allow attackers to access internal resources and perform unauthorized requests.
5
Which software versions are affected by CVE-2022-28090?
CVE-2022-28090 specifically affects Jspxcms version 10.2.0.