Record summary

CVE-2022-1815 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 18.1.2affected

Nuclei templates

1
ProjectDiscoveryHIGHDrawio <18.1.2 - Server-Side Request ForgeryCVSS 7.5

Drawio before 18.1.2 is susceptible to server-side request forgery via the /service endpoint in jgraph/drawio. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources or services.

Remediation

Upgrade Drawio to version 18.1.2 or later to mitigate the SSRF vulnerability.

WeaknessesCWE-918CWE-200
Authorsamit-jd
Template tagscvecve2022huntrdrawiossrfoastossjgraphdiagramsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:diagrams:drawio:*:*:*:*:*:*:*:*
Shodan: http.title:"flowchart maker"
FOFA: title="flowchart maker"
Google: intitle:"flowchart maker"

Source: ProjectDiscovery

References

3