Description
A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The flaw is a server‑side request forgery in the ckditor::saveRemote function of the WuzhiCMS Remote Image Fetch component, which can be triggered by manipulating the source[] argument. An attacker can craft requests that cause the server to fetch arbitrary URLs, potentially accessing internal network resources or exfiltrating data. The description notes that exploits have been published and may be used by remote attackers.

Affected Systems

All WuzhiCMS installations up to and including version 4.1.0 are affected. The vulnerable component resides in coreframe/app/attachment/index.php and is part of the Remote Image Fetch feature. Any system that has not applied a later release and still uses this feature remains vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating a moderate severity. The EPSS score of less than 1% reflects a low probability of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is remote; an attacker only needs to send a crafted HTTP request containing a manipulated source[] parameter to the vulnerable endpoint, after which the server will perform outbound requests to the supplied URLs.

Generated by OpenCVE AI on September 18, 2026 at 05:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any WuzhiCMS updates that address this SSRF flaw.
  • Disable or restrict the Remote Image Fetch feature to prevent the application from initiating external URL requests.
  • Configure network or firewall rules to block the web server from making outbound HTTP requests to untrusted or internal IP ranges.

Generated by OpenCVE AI on September 18, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery
First Time appeared Wuzhicms
Wuzhicms wuzhicms
Weaknesses CWE-918
CPEs cpe:2.3:a:wuzhicms:wuzhicms:*:*:*:*:*:*:*:*
Vendors & Products Wuzhicms
Wuzhicms wuzhicms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Wuzhicms Wuzhicms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:45:58.672Z

Reserved: 2026-09-16T07:43:37.652Z

Link: CVE-2026-92380

cve-icon Vulnrichment

Updated: 2026-09-16T15:45:48.272Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:01.317

Modified: 2026-09-16T17:53:40.500

Link: CVE-2026-92380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)