CVE-2022-28117 describes a Server-Side Request Forgery (SSRF) vulnerability in the feed_parser class of Navigate CMS version 2.9.4. This flaw allows authenticated attackers to inject arbitrary URLs into the feed parameter, forcing the application to make unauthorized requests. Rated 4.9 MEDIUM on the CVSS scale, the vulnerability has a network attack vector and high integrity impact, though it requires high privileges for exploitation. While not actively exploited in the wild or on the KEV catalog, public exploit code and Nuclei templates are available, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9.4CPE matchmatch criteria | cpe:2.3:a:naviwebs:navigate_cms:2.9.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.