High severity7.5NVD Advisory· Published May 23, 2022· Updated Jun 17, 2026
CVE-2022-28997
CVE-2022-28997
Description
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- CSZCMS/CSZCMSdescription
- Range: <=1.3.0
Patches
Vulnerability mechanics
References
5- i.imgur.com/BwWTfYU.pngnvdExploitThird Party Advisory
- i.imgur.com/S1F7MaJ.pngnvdExploitThird Party Advisory
- i.imgur.com/pzWjkXI.pngnvdExploitThird Party Advisory
- i.imgur.com/xxjxnGk.pngnvdExploitThird Party Advisory
- packetstormsecurity.com/files/166613/CSZCMS-1.3.0-SSRF-LFI-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.