Executive brief
Aimeos Pagible CMS, a content management system, is vulnerable to a security flaw in its administrative proxy feature. An attacker with basic access could bypass security checks to reach internal network resources or cloud metadata services that are not intended to be public. This could lead to the exposure of sensitive internal configuration data or cloud credentials.
Technical details
The administrative proxy route (`cmsproxy`) in Aimeos Pagible CMS is vulnerable to a Server-Side Request Forgery (SSRF) attack due to a Time-of-Check to Time-of-Use (TOCTOU) race condition. The `AdminController::proxy` validates target URLs using `isValidUrl`, which performs a DNS lookup to block private IP ranges. However, the subsequent request made via Guzzle performs a second DNS lookup. An attacker can use a malicious DNS server with a TTL of 0 to provide a 'safe' IP during the check and an internal/private IP (such as 169.254.169.254) during the actual request. This allows the attacker to bypass validation and access internal network resources or cloud metadata endpoints. The issue is fixed in version 0.10.4.
Affected products
- Aimeos Pagible CMS < 0.10.4
Timeline
- 2026-05-25: disclosed
- 2026-06-26: advisory
- 2026-06-26: patched
References
- https://api.github.com/users/PomPomSaturin
- https://github.com/PomPomSaturin
- https://api.github.com/users/PomPomSaturin/gists%7B/gist_id%7D
- https://api.github.com/users/PomPomSaturin/repos
- https://avatars.githubusercontent.com/u/248346576?v=4
- https://api.github.com/users/PomPomSaturin/events%7B/privacy%7D