First published: Thu Apr 28 2022(Updated: )
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Naviwebs Navigate CMS | =2.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28117 is a Server-Side Request Forgery (SSRF) vulnerability in the feed_parser class of Navigate CMS v2.9.4.
CVE-2022-28117 allows remote attackers to force Navigate CMS v2.9.4 to make arbitrary requests by injecting arbitrary URLs into the feed parameter.
The severity of CVE-2022-28117 is medium with a CVSS score of 4.9.
To fix CVE-2022-28117 in Navigate CMS v2.9.4, it is recommended to update to a newer version, such as Navigate CMS v2.9.5, which addresses the vulnerability.
You can find more information about CVE-2022-28117 in the following references: [Packet Storm Security](http://packetstormsecurity.com/files/167063/Navigate-CMS-2.9.4-Server-Side-Request-Forgery.html), [Navigate CMS Blog](https://www.navigatecms.com/en/blog/development/navigate_cms_update_2_9_5), [YouTube video](https://www.youtube.com/watch?v=4kHW95CMfD0).