← Späť na vyhľadávanie CVE

CVE-2021-47958

CouchCMS

Popis

CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.

CVSS 4.3EPSS 0.23800000000000002%Riziko 0.44
Zobraziť zdroj
Zverejnené
2026-05-15 19:16:54
Dotknuté verzie
<=2.2.1
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N