Impact
October CMS contains a server‑side request forgery in the validateExternalImageHost function of the SSRF Protection component. This flaw enables an attacker to craft image URLs that cause the CMS to make arbitrary HTTP requests to internal or external hosts, potentially leaking sensitive data or interacting with backend services. The vulnerability permits remote exploitation and could lead to unauthorized data exposure or further lateral movement within an organization’s network.
Affected Systems
The issue affects October CMS releases up through version 4.3.4 when the SSRF Protection component is present. A fix was introduced in October CMS 4.3.5, which removes the vulnerable logic. Systems running 4.3.4 or earlier should be upgraded to 4.3.5 or later to eliminate the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. The attack vector is remote, and the vulnerability has become publicly exploitable, though it is not yet listed in the CISA KEV catalog and no EPSS score is available. Attackers can trigger the SSRF by supplying malicious image URLs to the CMS, which the validateExternalImageHost function then resolves, allowing requests to any target host specified by the attacker.
OpenCVE Enrichment