References https://nvd.nist.gov/vuln/detail/CVE-2022-1815 https://www.cve.org/CVERecord?id=CVE-2022-1815 https://vuldb.com/vuln/200684 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1815.yaml https://pentest-tools.com/vulnerabilities-exploits/drawio-1812-server-side-request-forgery_2201 https://huntr.dev/bounties/6e856a25-9117-47c6-9375-52f78876902f https://github.com/jgraph/drawio/commit/c287bef9101d024b1fd59d55ecd530f25000f9d8 https://app.opencve.io/cve/CVE-2022-1815
Related VulnerabilitiesPoCCVE-2024-9487: GitHub Enterprise - SAML Authentication BypassPoCCVE-2018-1000600: Jenkins GitHub Plugin <=1.29.1 - Server-Side Request ForgeryPoCCVE-2024-0200: Github Enterprise - Remote Code ExecutionPoCCVE-2025-53624: Docusaurus Gists Plugin < 4.0.0 - GitHub Personal Access Token ExposurePoCgithub-gist-csp-bypass: Content-Security-Policy Bypass - GitHub GistPoCgithub-app-token: Github App TokenPoCgithub-oauth-token: Github OAuth Access TokenPoCgithub-personal-token: Github Personal TokenPoCgithub-refresh-token: Github Refresh TokenPoCgithub-login-check: Github Login CheckPoCgithub-workflows-disclosure: Github Workflow DisclosurePoCgithub-personal-access: GitHub Personal Access TokenPoCsetup-github-enterprise: Setup GitHub Enterprise - Detect