Record summary

CVE-2022-45835 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.

Description

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.0.15affected
VulnCheckVersion data not supplied

Default status: unknown

CVE ListThrough 1.0.15affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request ForgeryCVSS 7.5

WordPress PhonePe Payment Solutions plugin through 1.0.15 is susceptible to server-side request forgery. An attacker can cause a website to execute website requests to an arbitrary domain, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

An attacker can exploit this vulnerability to send arbitrary HTTP requests from the server, potentially leading to unauthorized access to internal resources or performing actions on behalf of the server.

Remediation

Fixed in version 2.0.0.

WeaknessesCWE-918
Authorstheamanrawat
Template tagscvecve2022ssrfwordpresswp-pluginwpphonepe-payment-solutionsunauthoastphonepevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:phonepe:phonepe:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2