Impact
The flaw is a server‑side request forgery in the ckditor::saveRemote function of the WuzhiCMS Remote Image Fetch component, which can be triggered by manipulating the source[] argument. An attacker can craft requests that cause the server to fetch arbitrary URLs, potentially accessing internal network resources or exfiltrating data. The description notes that exploits have been published and may be used by remote attackers.
Affected Systems
All WuzhiCMS installations up to and including version 4.1.0 are affected. The vulnerable component resides in coreframe/app/attachment/index.php and is part of the Remote Image Fetch feature. Any system that has not applied a later release and still uses this feature remains vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate severity. The EPSS score of less than 1% reflects a low probability of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is remote; an attacker only needs to send a crafted HTTP request containing a manipulated source[] parameter to the vulnerable endpoint, after which the server will perform outbound requests to the supplied URLs.
OpenCVE Enrichment