PT-2025-37258 · Unknown · Instantcms
Szczurowsky
+1
·
Published
2025-09-11
·
Updated
2025-09-24
·
CVE-2025-59055
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
InstantCMS versions through 2.17.3
Description:
InstantCMS is a free and open source content management system. A blind Server-Side Request Forgery (SSRF) vulnerability exists that allows authenticated remote attackers to make arbitrary HTTP/HTTPS requests via the
package parameter. This is possible within the installer functionality. Exploitation can lead to scanning the local network, calling local services and their functions, conducting a Denial-of-Service (DoS) attack, and disclosing a server's real IP address if it is behind a reverse proxy. It is also possible to exhaust server resources by sending numerous requests.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Instantcms