PT-2026-41339 · Couchcms · Couchcms

Xxcdd

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2021-47958

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2021-47958

Affected Products

Couchcms