vendor:
CouchCMS
by:
xxcdd
8.8
CVSS
HIGH
Server-Side Request Forgery (SSRF)
918
CWE
Product Name: CouchCMS
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:couchcms:couchcms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2021
CouchCMS 2.2.1 – SSRF via SVG file upload
An issue was discovered in CouchCMS v2.2.1 that allows SSRF via an /couch/includes/kcfinder/browse.php SVG upload. The upload URL is /couch/includes/kcfinder/browse.php?nonce=[yournonce]&type=file&CKEditor=f_main_content&CKEditorFuncNum=1&langCode=en and the SVG content contains an xlink:href attribute pointing to a malicious IP address.
Mitigation:
Upgrade to the latest version of CouchCMS.