← Volver al buscador de CVEs

CVE-2026-49262

Aimeos Pagible

Descripción

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL validation phase and the actual HTTP request phase, allowing attackers to access internal network resources and cloud metadata endpoints. Version 0.10.4 fixes the issue.

CVSS 3EPSS 0.131%Riesgo 0.3
Ver fuente
Publicación
2026-08-12 15:17:35
Versiones afectadas
<0.10.4
Tipo
Aplicación web
Última modificación
2026-08-12 16:17:03
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N