PT-2026-7474 · Doracms · Doracms
Lennon Chia
·
Published
2026-02-10
·
Updated
2026-02-11
·
CVE-2026-25870
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
DoraCMS versions prior to 3.1
Description
The software contains a server-side request forgery (SSRF) issue in its UEditor remote image fetch functionality. The application takes user-provided URLs and makes server-side HTTP or HTTPS requests without proper validation or restrictions. The implementation lacks allowlists, blocks for internal IP addresses, and request timeouts or response size limits. An attacker can exploit this to make the server send requests to any host, including internal network resources, potentially allowing network scanning and denial of service.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doracms