PT-2026-25692 · Raytha+1 · Raytha
Daniel Basta
·
Publicado
2026-03-16
·
Atualizado
2026-03-16
·
CVE-2025-69239
CVSS v4.0
5.1
Média
| Vetor | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Raytha CMS versions prior to 1.4.6
Description
Raytha CMS has a Server-Side Request Forgery (SSRF) issue in the “Themes - Import from URL” feature. An attacker with high privileges can provide a URL to redirect server-side HTTP requests. The vulnerable feature allows an attacker to control the destination of server-side requests, potentially leading to unauthorized access to internal resources or data exfiltration.
Recommendations
Update Raytha CMS to version 1.4.6 or later.
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Raytha