CVE-2022-45362
WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)
Record summary
CVE-2022-45362 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 2.7.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Paytm Payment Gateway <=2.7.0 - Server-Side Request ForgeryCVSS 6.5
WordPress Paytm Payment Gateway plugin through 2.7.0 contains a server-side request forgery vulnerability. An attacker can cause a website to execute website requests to an arbitrary domain, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Unauthenticated attackers can exploit server-side request forgery through the url parameter in the curltest action to make arbitrary HTTP requests from the server, potentially accessing internal network resources and sensitive data.
Remediation
Update to the latest version of the WordPress Paytm Payment Gateway plugin (2.7.0) or apply the vendor-supplied patch.
Source: ProjectDiscovery