Impact
Aimeos Pagible CMS versions prior to 0.10.4 contain a time‑of‑check to time‑of‑use race condition in the administrative proxy route (cmsproxy), allowing a server‑side request forgery that can resolve requests to internal network addresses or cloud metadata services, potentially exposing sensitive internal information.
Affected Systems
The vulnerability affects all installations of Aimeos Pagible CMS with a version of 0.10.3 or earlier. Applying the 0.10.4 release or later removes the flaw.
Risk and Exploitability
The CVSS score of 3 indicates low severity, and the EPSS score is not available, so the probability of exploitation is presently unknown. Based on the description, the attack vector likely requires access to the cmsproxy route, which is normally restricted to authenticated administrators, meaning that an attacker would need administrative credentials or another means to reach the CMS administrative panel. Although the vulnerability is low severity, exploitation could allow access to internal resources, cloud metadata endpoints, or other private data, and the flaw is not currently listed in the CISA KEV catalog, reducing immediate threat potential but still warranting remediation.
OpenCVE Enrichment
Github GHSA