Impact
The flaw exists in the /index/image/headers functionality of Qibo CMS 1.0. An attacker can manipulate the argument "starts" sent to that endpoint and cause the web server to perform an outbound HTTP request to an arbitrary target. This leads to server‑side request forgery, enabling the attacker to reach internal or external services, exfiltrate data, or trigger actions without client interaction. The underlying weakness matches CWE‑918.
Affected Systems
Qibo CMS version 1.0. The vulnerability was identified in an unknown function of the /index/image/headers file. No other versions or products were cited, so only the 1.0 release is known to be affected.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity level. No EPSS score is available, so the current likelihood of exploitation cannot be quantified from the data. The issue is not listed in CISA’s KEV catalog, implying no publicly confirmed active exploitation at the time of assessment. The description states the attack can be launched remotely, and the exploit has been publicly disclosed, so an adversary can attempt use against any exposed instance of the problematic endpoint. Because the vendor did not acknowledge or respond, no official fix exists yet, raising the importance of mitigation measures.
OpenCVE Enrichment