PT-2026-67898 · Poesis · Rhymix Cms
CVE-2026-18856
·
Published
2026-08-05
·
Updated
2026-08-05
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Poesis Rhymix CMS versions prior to 2.1.34
Description
An issue exists in the Data Import Module within the
procImporterAdminCheckXmlFile() function of the modules/importer/importer.admin.controller.php file. Remote manipulation of the filename argument allows for server-side request forgery, a technique where an attacker induces the server to make requests to an unintended location.Recommendations
Upgrade to version 2.1.34.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rhymix Cms