PT-2026-34665 · Unknown · Socialengine
Egidio Romano
·
Published
2026-04-23
·
Updated
2026-04-27
·
CVE-2026-41461
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SocialEngine versions prior to 7.8.1
Description
A blind server-side request forgery exists in the "/core/link/preview" endpoint. The issue occurs because user-supplied input passed via the
uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can provide arbitrary URLs, including internal network and loopback addresses, forcing the server to issue HTTP requests to attacker-controlled destinations. This allows for internal network enumeration and access to services not intended to be externally reachable.Recommendations
Update to a version later than 7.8.0.
As a temporary workaround, restrict access to the "/core/link/preview" endpoint or avoid using the
uri parameter until a patch is applied.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Socialengine