PT-2026-7474 · Doracms · Doracms

Lennon Chia

·

Publicado

2026-02-10

·

Atualizado

2026-02-11

·

CVE-2026-25870

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DoraCMS versions prior to 3.1
Description The software contains a server-side request forgery (SSRF) issue in its UEditor remote image fetch functionality. The application takes user-provided URLs and makes server-side HTTP or HTTPS requests without proper validation or restrictions. The implementation lacks allowlists, blocks for internal IP addresses, and request timeouts or response size limits. An attacker can exploit this to make the server send requests to any host, including internal network resources, potentially allowing network scanning and denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25870

Produtos afetados

Doracms