PT-2026-34813 · Xibo · Xibo

Swarnimbandekar

·

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-31955

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions prior to 4.4.1
Description An authenticated Server-Side Request Forgery (SSRF) allows users with DataSet permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be used to scan internal infrastructure, access local cloud metadata endpoints such as AWS IMDS, interact with unauthenticated internal services, or exfiltrate data. Exploitation requires an authorized user to possess the privilege to use the "Add DataSet" button for creating additional DataSets independently to Layouts.
Recommendations Upgrade to version 4.4.1. Revoke the privilege to use the "Add DataSet" button from untrusted users as a temporary workaround.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31955

Affected Products

Xibo