PT-2026-34665 · Unknown · Socialengine

Egidio Romano

·

Published

2026-04-23

·

Updated

2026-04-27

·

CVE-2026-41461

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SocialEngine versions prior to 7.8.1
Description A blind server-side request forgery exists in the "/core/link/preview" endpoint. The issue occurs because user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can provide arbitrary URLs, including internal network and loopback addresses, forcing the server to issue HTTP requests to attacker-controlled destinations. This allows for internal network enumeration and access to services not intended to be externally reachable.
Recommendations Update to a version later than 7.8.0. As a temporary workaround, restrict access to the "/core/link/preview" endpoint or avoid using the uri parameter until a patch is applied.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41461

Affected Products

Socialengine