CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.
Metrics
Affected Vendors & Products
References
History
Fri, 15 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources. | |
| Title | CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload | |
| First Time appeared |
Couchcms
Couchcms couchcms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:couchcms:couchcms:1.3.5:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:1.4.5:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:1.4.7:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:1.4:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.0:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.1:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.2:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Couchcms
Couchcms couchcms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T22:56:00.813Z
Reserved: 2026-02-01T11:24:18.720Z
Link: CVE-2021-47958
Updated: 2026-05-15T22:12:41.351Z
Status : Received
Published: 2026-05-15T19:16:54.623
Modified: 2026-05-15T19:16:54.623
Link: CVE-2021-47958
No data.
OpenCVE Enrichment
Updated: 2026-05-15T22:00:12Z