First published: Tue Nov 22 2022(Updated: )
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced Custom Fields | <=3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40842 is considered a critical vulnerability due to its potential for server-side request forgery (SSRF).
To fix CVE-2022-40842, upgrade to a version of NdkAdvancedCustomizationFields that is newer than 3.5.0 which has addressed this vulnerability.
CVE-2022-40842 affects the NdkAdvancedCustomizationFields plugin for PrestaShop version 3.5.0 and below.
CVE-2022-40842 is classified as a server-side request forgery (SSRF) vulnerability.
The potential impacts of CVE-2022-40842 include unauthorized access to internal systems and sensitive data exposure.