CVE-2022-40357: SSRF
Published Sep 20, 2022
·Updated
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zbusers/plugin/UEditor/php/actioncrawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the source parameter.
Affected Software
1 affected component
ZblogCN Z-blogphp<=1.7.2
Event History
Sep 20, 2022
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40357?
CVE-2022-40357 has been classified with a high severity due to its Server-Side Request Forgery (SSRF) risk.
2
How do I fix CVE-2022-40357?
To fix CVE-2022-40357, upgrade Z-BlogPHP to version 1.7.3 or higher to patch the SSRF vulnerability.
3
What does CVE-2022-40357 affect?
CVE-2022-40357 affects Z-BlogPHP versions up to and including 1.7.2.
4
What type of vulnerability is CVE-2022-40357?
CVE-2022-40357 is a Server-Side Request Forgery (SSRF) vulnerability.
5
Can CVE-2022-40357 be exploited remotely?
Yes, CVE-2022-40357 can be exploited remotely by injecting arbitrary URLs into the source parameter.