Impact
An authenticated Server‑Side Request Forgery (SSRF) exists in the Remote DataSet functionality of Xibo CMS. Users possessing DataSet creation privileges can trigger the server to make arbitrary HTTP requests to any internal or external address. This capability enables coverage of internal network discovery, extraction of cloud metadata such as AWS IMDS, interaction with unauthenticated internal services, and potential exfiltration of sensitive data. The attack requires legitimate user credentials but bypasses the intended access boundaries of the CMS.
Affected Systems
The vulnerability affects Xibo CMS from Xibo Signage, specifically all releases prior to version 4.4.1. The issue is tied to users with the DataSet permission and the ability to use the "Add DataSet" function. No other products or vendor versions are listed.
Risk and Exploitability
The CVSS score is 4.9, indicating low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with the specific DataSet privilege, and the SSRF can be used to probe internal resources or other exposed services.
OpenCVE Enrichment