PT-2026-7474 · Doracms · Doracms

Lennon Chia

·

Published

2026-02-10

·

Updated

2026-02-11

·

CVE-2026-25870

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DoraCMS versions prior to 3.1
Description The software contains a server-side request forgery (SSRF) issue in its UEditor remote image fetch functionality. The application takes user-provided URLs and makes server-side HTTP or HTTPS requests without proper validation or restrictions. The implementation lacks allowlists, blocks for internal IP addresses, and request timeouts or response size limits. An attacker can exploit this to make the server send requests to any host, including internal network resources, potentially allowing network scanning and denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-25870

Affected Products

Doracms