Executive brief
CouchCMS, a content management system designed for web designers, is vulnerable to a security flaw that allows logged-in users to perform unauthorized network requests. By uploading a specially crafted image file, an attacker could force the server to interact with internal systems or external websites. This could be used to probe internal network services that are not normally accessible from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in CouchCMS version 2.2.1 and earlier. The flaw is located in the KCFinder component, specifically within the `browse.php` endpoint used for file management. Authenticated attackers can upload malicious SVG files containing external entity references or image tags with remote `xlink:href` attributes. When the server processes these files, it attempts to fetch the remote resources, allowing the attacker to make arbitrary HTTP requests from the server's IP address. This can be leveraged to scan internal networks, bypass firewalls, or interact with internal services.
Affected products
- CouchCMS CouchCMS 2.2.1 and earlier
Timeline
- 2021-01-25: disclosed: Vulnerability discovered and reported by xxcdd
- 2021-03-19: other: Exploit code published on Exploit-DB
- 2026-05-15: advisory: CVE published/updated in NVD dataset