S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-28117 Scanner

CVE-2022-28117 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Navigate CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-28117
4.9
CVSS

A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the feed parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Navigate CMS is a robust content management system designed for use by individuals and organizations requiring a dedicated publishing platform. The CMS is well-suited for managing blogs, news sites, and online magazines, and its user-friendly interface allows users to easily create, manage, and publish content. Additionally, it supports multiple users with varying permissions, so teams can easily collaborate on content creation and management.

The vulnerability code CVE-2022-28117 was recently detected in Navigate CMS v2.9.4, a Server-Side Request Forgery (SSRF) vulnerability. An SSRF attack is typically used by hackers to force an application to make unauthorized requests by injecting arbitrary URLs into the affected parameter. Exploitation of this vulnerability can allow an attacker to access internal resources and retrieve sensitive data, including private keys, credentials, and other confidential information.

If an attacker successfully exploits this vulnerability, they can send arbitrary HTTP requests, such as visiting a target website or accessing privileged information, using the authenticated user's identity. This can lead to significant data breaches, including unauthorized data access and data leaks, leading to reputational and financial losses. As a result, navigating CMS users are urged to take proactive measures to protect against this vulnerability.

In conclusion, security is a top concern for individuals and organizations alike. By leveraging the pro features of the s4e.io platform, readers can quickly learn about vulnerabilities in their digital assets. This platform offers comprehensive vulnerability scanning, risk assessment, and reporting capabilities, enabling users to navigate threats and protect their digital assets effectively. Don't take security for granted - stay informed, stay vigilant, and stay safe.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against the Navigate CMS SSRF vulnerability, as follows:

  • Update Navigate CMS to the latest available version.
  • Ensure that the system is secured and regularly monitored.
  • Use firewalls and intrusion detection systems to prevent unauthorized access.
  • Disable unnecessary routes and restrict access to essential modules.
  • Educate users about the potential risk of SSRF vulnerabilities and how to avoid them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.