header-logo
Suggest Exploit
vendor:
CouchCMS
by:
xxcdd
8.8
CVSS
HIGH
Server-Side Request Forgery (SSRF)
918
CWE
Product Name: CouchCMS
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:couchcms:couchcms
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows 7
2021

CouchCMS 2.2.1 – SSRF via SVG file upload

An issue was discovered in CouchCMS v2.2.1 that allows SSRF via an /couch/includes/kcfinder/browse.php SVG upload. The upload URL is /couch/includes/kcfinder/browse.php?nonce=[yournonce]&type=file&CKEditor=f_main_content&CKEditorFuncNum=1&langCode=en and the SVG content contains an xlink:href attribute pointing to a malicious IP address.

Mitigation:

Upgrade to the latest version of CouchCMS.
Source

Exploit-DB raw data: