Sceawere

Vulnerability Detail

CVE-2026-101005UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

October CMS SSRF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
n/a
Product
October CMS
Attack Type
Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrade the affected component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-28T07:17:19.827Z",
  "pubdate": "2026-09-28T07:17:19.827Z",
  "executiveSummary": "October CMS versions up to 4.3.4 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability due to insufficient validation of external image hosts.\nThis vulnerability resides within the System/Classes/ResizeImages.php file, specifically affecting the validateExternalImageHost function intended for SSRF protection.\nThe flaw permits remote attackers to force the server to initiate unauthorized HTTP requests to arbitrary destinations, including internal network resources that are otherwise inaccessible from the public internet.\nExploitation allows for potential data exfiltration, internal service reconnaissance, and the bypass of firewall or network security controls, posing a significant risk to the integrity and confidentiality of the host infrastructure.\nThe vulnerability is currently subject to public exploits, necessitating immediate remediation to prevent unauthorized abuse.\nUsers are advised to upgrade to version 4.3.5 or later to address the root cause of the validation failure.",
  "technicalDetails": "The SSRF vulnerability in October CMS originates from an incomplete implementation of input validation within the validateExternalImageHost function, located in System/Classes/ResizeImages.php. This function is designed to serve as a security gateway to prevent the application from processing malicious or unauthorized external image URLs, yet it fails to properly sanitize or restrict the hostnames provided in image resizing requests.\nWhen the application attempts to process an external image through the ResizeImages component, the validateExternalImageHost function is invoked to verify the target host. Because the validation logic is flawed, an attacker can supply specially crafted URLs that bypass the intended security checks. By manipulating the host parameter, an attacker can influence the underlying HTTP client utilized by the component to send requests to arbitrary internal or external IP addresses and domain names.\nThe attack flow begins when an authenticated or unauthenticated attacker, depending on specific endpoint access, submits a request to the affected component containing a maliciously crafted URL pointing to an internal resource (e.g., http://127.0.0.1 or http://169.254.169.254). The application, acting on behalf of the server, retrieves the content from the target URL, effectively turning the October CMS instance into a proxy for the attacker's traffic.\nThis behavior facilitates several post-exploitation scenarios, including the mapping of the internal network architecture, querying internal metadata services in cloud environments to retrieve sensitive configuration data, and interacting with internal-only administrative interfaces that lack secondary authentication layers. Because the request originates from the web server itself, it is often trusted by internal services, allowing the attacker to bypass perimeter security measures and access local services that are not exposed to the public network.\nThe issue persists in all October CMS installations running versions up to 4.3.4. Successful exploitation does not inherently require high-level privileges if the component is accessible via standard user interactions, making it a critical threat vector for environments where the resize functionality is exposed. The absence of strict allow-listing for external image hosts renders the current validation mechanism ineffective against common SSRF bypass techniques such as DNS rebinding or the use of specific character encodings."
}
CVE-2026-101005: October CMS SSRF Vulnerability (HIGH Severity, CVSS: 7.3) | Sceawere