Record summary

CVE-2022-1713 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 18.0.4affected

Nuclei templates

1
ProjectDiscoveryHIGHDrawio <18.0.4 - Server-Side Request ForgeryCVSS 7.5

Drawio prior to 18.0.4 is vulnerable to server-side request forgery. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

Impact

Successful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources and potential data leakage.

Remediation

Upgrade Drawio to version 18.0.4 or later to mitigate the SSRF vulnerability.

WeaknessesCWE-918
Authorspikpikcu
Template tagscvecve2022drawiossrfosshuntrdiagramsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:diagrams:drawio:*:*:*:*:*:*:*:*
Shodan: http.title:"Flowchart Maker"
Shodan: http.title:"flowchart maker"
FOFA: title="flowchart maker"
Google: intitle:"flowchart maker"

Source: ProjectDiscovery

References

3