Record summary

CVE-2022-2756 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 0.5.4.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMKavita <0.5.4.1 - Server-Side Request ForgeryCVSS 6.5

Kavita before 0.5.4.1 is susceptible to server-side request forgery in GitHub repository kareadita/kavita. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability can result in unauthorized access to sensitive information or systems, leading to potential data breaches or further attacks.

Remediation

Fixed in 0.5.4.1.

WeaknessesCWE-918
Authorstheamanrawat
Template tagscvecve2022ssrfkavitaauthenticatedhuntrintrusivekavitareadervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kavitareader:kavita:*:*:*:*:*:*:*:*
Shodan: title:"kavita"
Shodan: http.title:"kavita"
FOFA: title="kavita"
Google: intitle:"kavita"

Source: ProjectDiscovery

References

3