.. / CVE-2022-1815

Exploit for Drawio <18.1.2 - Server-Side Request Forgery (CVE-2022-1815)

Description:

Drawio before 18.1.2 is susceptible to server-side request forgery via the /service endpoint in jgraph/drawio. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Nuclei Template

View the template here CVE-2022-1815.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-1815.yaml
Copy

References:

https://huntr.dev/bounties/6e856a25-9117-47c6-9375-52f78876902f/
https://nvd.nist.gov/vuln/detail/CVE-2022-1815
https://github.com/jgraph/drawio/commit/c287bef9101d024b1fd59d55ecd530f25000f9d8
https://huntr.dev/bounties/6e856a25-9117-47c6-9375-52f78876902f
https://github.com/ARPSyndicate/kenzer-templates