Impact
The vulnerability is a Server‑Side Request Forgery (SSRF) in the UEditor catchimage endpoint of Feehi CMS 2.1.1. The endpoint fetches images from remote URLs, but the private‑IP validation that should block loopback and link‑local addresses is omitted. An attacker can thus instruct the service to request internal URLs and determine whether internal HTTP services respond differently, leaking information about the internal network.
Affected Systems
Only the Feehi CMS 2.1.1 distribution contains this flaw. The vulnerability exists in the catchimage handler that retrieves images via HTTP requests. No other versions or products are documented. Administrators of installations running this specific CMS version should verify their deployment.
Risk and Exploitability
Because the flaw allows external input to trigger server‑initiated requests, the attack vector is remote, via an HTTP request to the vulnerable endpoint. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that publicly available exploits may not yet be widespread. Nevertheless, the omission of loopback and link‑local address checks creates a high‑impact condition that can lead to internal network reconnaissance or further exploitation of exposed internal services. The severity is naturally high, and mitigation should be prioritized even in the absence of published CVSS metrics.
OpenCVE Enrichment