← Zurück zur CVE-Suche

CVE-2026-73629

serendipity

Beschreibung

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminImagesAdd permission can bypass the filter using alternate address formats to request internal services and retrieve response bodies through the public uploads directory.

CVSS 8.5EPSS 0.189%Risiko 0.86
Quelle öffnen
Veröffentlicht
2026-08-13 12:17:28
Betroffene Versionen
<2.6.0
Typ
Webanwendung
Zuletzt geändert
2026-08-14 19:18:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N