Aller au contenu

Fiche vulnérabilité

CVE-2022-40296 : faille critique phppointofsale php point of sale (CVSS 9.8)

Description

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
31 oct. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • phppointofsale php point of sale

Références

Rechercher une autre vulnérabilité dans la base CVE