Impact
The vulnerability is a server‑side request forgery in the upload‑from‑URL feature. When the request follows an HTTP redirect, the CMS ignores its private‑IP blacklist, allowing authenticated users to force the server to issue requests to internal network addresses. This can reveal and expose services located behind firewalls, giving attackers knowledge and access to resources beyond the web perimeter. The flaw is a classic SSRF identified by CWE‑918.
Affected Systems
The affected product is Instantsoft ICMS2, versions earlier than 2.18.2. All installations of the open‑source CMS that have not applied the 2.18.2 update are vulnerable. The vendor announced a fix in commit 04b8fe0e and in the GitHub advisory.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and the absence of an EPSS score and KEV listing means there is no evidence of widespread exploitation. Attackers must be authenticated to use the vulnerable upload feature, making the risk limited to the scope of legitimate user accounts. The SSRF can be triggered over the web interface, so the vulnerability is network‑accessible but requires valid credentials. Although the impact is limited, the ability to enumerate internal services may assist attackers in planning further attacks.
OpenCVE Enrichment