github.com
https://github.com/kareadita/kavita/commit/9c31f7e7c81b919923cb2e3857439ec0d16243e4 CVE-2022-2756
MEDIUMNuclei
Server-Side Request Forgery (SSRF) in kareadita/kavita
Record summary
CVE-2022-2756 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
kareadita/kavitaBrowse kareadita / kareadita/kavita | CVE List | Before 0.5.4.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMKavita <0.5.4.1 - Server-Side Request ForgeryCVSS 6.5
Kavita before 0.5.4.1 is susceptible to server-side request forgery in GitHub repository kareadita/kavita. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability can result in unauthorized access to sensitive information or systems, leading to potential data breaches or further attacks.
Remediation
Fixed in 0.5.4.1.
WeaknessesCWE-918
Authorstheamanrawat
Template tagscvecve2022ssrfkavitaauthenticatedhuntrintrusivekavitareadervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kavitareader:kavita:*:*:*:*:*:*:*:*
Shodan: title:"kavita"
Shodan: http.title:"kavita"
FOFA: title="kavita"
Google: intitle:"kavita"
https://huntr.dev/bounties/95e7c181-9d80-4428-aebf-687ac55a9216/ https://github.com/kareadita/kavita https://github.com/kareadita/kavita/commit/9c31f7e7c81b919923cb2e3857439ec0d16243e4 https://nvd.nist.gov/vuln/detail/CVE-2022-2756
Source: ProjectDiscovery
References
3huntr.devConfirmation
https://huntr.dev/bounties/95e7c181-9d80-4428-aebf-687ac55a9216 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-2756