PT-2026-40251 · Xibo Cms · Xibo Cms
Published
2026-05-12
·
Updated
2026-05-12
·
CVE-2026-42141
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xibo versions prior to 4.4.1
Description
An authenticated Server-Side Request Forgery (SSRF) in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to internal or external network resources. This can be used to scan internal infrastructure, access local cloud metadata endpoints such as AWS IMDS (Instance Metadata Service, which provides data about a running instance), interact with unauthenticated internal services, or exfiltrate data.
Recommendations
Update to version 4.4.1.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xibo Cms