Junglewise Threat Intelligence

CVE-2017-5518: GeniXCMS SSRF in media-file upload feature

CVE-2017-5518 · Severity: high · CVSS 7.4 · Published 2017-01-17

Technologies: Metalgenix Genixcms. Vendors: Metalgenix.

Executive brief

GeniXCMS, a content management system, contains a security flaw in its media upload feature. An attacker can exploit this to force the server to make unauthorized requests to internal systems or external websites. This could allow an attacker to scan private internal networks or interact with internal services that are not intended to be accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in GeniXCMS versions up to and including 0.0.8. The vulnerability is located within the media-file upload functionality, which fails to properly validate user-supplied URLs when fetching remote files. A remote attacker can provide a URL pointing to internal network resources (e.g., intranet IP addresses) or loopback interfaces. This allows the attacker to use the server as a proxy to conduct internal port scanning or interact with internal services that are otherwise protected by a firewall. The issue was identified in GitHub issue #64 and is addressed in subsequent patches.

Affected products

  • GeniXCMS GeniXCMS through 0.0.8

Timeline

  • 2017-01-17: disclosed
  • 2017-01-17: advisory

References

Related threats