CVE-2022-40357 | Z-BlogPHP up to 1.7.2 action_crawler.php Source server-side request forgery (Issue 336)
A vulnerability classified as critical has been found in Z-BlogPHP up to 1.7.2. This affects an unknown part of the file zb_users/plugin/UEditor/php/action_crawler.php. The manipulation of the argument Source leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2022-40357. It is possible to initiate the attack remotely. There is no exploit available.