CVE-2022-45835
WordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF)
Record summary
CVE-2022-45835 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.
Description
Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
PhonePe Payment SolutionsBrowse PhonePe / PhonePe Payment SolutionsDefault status: unaffected | CVE List | Through 1.0.15 | affected |
phonepeBrowse phonepe / phonepe | VulnCheck | Version data not supplied | |
phonepe_payment_solutionsBrowse phonepe / phonepe_payment_solutionsDefault status: unknown | CVE List | Through 1.0.15 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request ForgeryCVSS 7.5
WordPress PhonePe Payment Solutions plugin through 1.0.15 is susceptible to server-side request forgery. An attacker can cause a website to execute website requests to an arbitrary domain, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
An attacker can exploit this vulnerability to send arbitrary HTTP requests from the server, potentially leading to unauthorized access to internal resources or performing actions on behalf of the server.
Remediation
Fixed in version 2.0.0.
Source: ProjectDiscovery