CVE-2022-28117
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 23%
from disclosure to weapon0 days
Published on NVDApr 28
1st PoCApr 6
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/50921unverifiedgithubgithub.com/cheshireca7/CVE-2022-28117★ 2githubgithub.com/kimstars/POC-CVE-2022-28117★ 0cve_referencepacketstormsecurity.com/files/167063/Navigate-CMS-2.9.4-Server-Side-Request-Forgery.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.