Description
A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server-side Request Forgery
Action: Patch ASAP
AI Analysis

Impact

The flaw lies in the openConnection method of ThemeService.java in taisan tarzan‑cms 1.0.0. An attacker can forge the httpUrl argument, causing the application to establish a connection to any specified URL, which enables the server to fetch internal or arbitrary resources. This can lead to data exfiltration, network reconnaissance, or use as a stepping‑stone to further attacks against internal services, and the vulnerability is a classic server‑side request forgery (CWE‑918) that can be exploited remotely without authentication.

Affected Systems

taisan:tarzan‑cms version 1.0.0 is affected. No other products or versions were listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, but the flaw is publicly disclosed and can be leveraged remotely. It is not listed in the CISA KEV catalog. Because SSRF can expose internal network addresses or sensitive data, the risk to confidentiality and availability is significant if the attacker can reach the vulnerable endpoint on the admin interface.

Generated by OpenCVE AI on September 15, 2026 at 14:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest taisan tarzan‑cms release that removes the vulnerable openConnection method, if available.
  • If no official fix is available, disable or restrict access to the ThemeService admin endpoint, or block the HTTP URL parameter from accepting untrusted values.
  • Implement server‑side input validation to reject non‑trusted URLs, or unexpected schemes.

Generated by OpenCVE AI on September 15, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title taisan tarzan-cms Theme Download Function ThemeService.java openConnection server-side request forgery
First Time appeared Taisan
Taisan tarzan-cms
Weaknesses CWE-918
CPEs cpe:2.3:a:taisan:tarzan-cms:*:*:*:*:*:*:*:*
Vendors & Products Taisan
Taisan tarzan-cms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Taisan Tarzan-cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:54:40.488Z

Reserved: 2026-09-13T09:12:26.998Z

Link: CVE-2026-90710

cve-icon Vulnrichment

Updated: 2026-09-16T14:54:34.481Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T12:17:51.043

Modified: 2026-09-16T15:18:41.210

Link: CVE-2026-90710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)