What is CVE-2026-18856?
A server-side request forgery (SSRF) vulnerability exists in Poesis Rhymix CMS versions up to 2.1.33, affecting the 'procImporterAdminCheckXmlFile' function in 'modules/importer/importer.admin.controller.php'. Manipulation of the 'filename' argument allows unauthorized requests, potentially exposing internal network resources. Users should upgrade to the latest version immediately.
Azərbaycanca: Poesis Rhymix CMS-in 2.1.33-ə qədər versiyalarında, Data Import Module-un 'importer.admin.controller.php' faylındakı 'procImporterAdminCheckXmlFile' funksiyasında server-side request forgery (SSRF) zəifliyi aşkar edilib, 'filename' parametrinin manipulyasiyası ilə icazəsiz sorğular göndərilə bilər. Bu, təcavüzkarlara daxili şəbəkə resurslarına giriş imkanı yarada bilər. İstifadəçilərə ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which component of Poesis Rhymix CMS was the SSRF vulnerability discovered?
The vulnerability was found in the 'procImporterAdminCheckXmlFile' function of the Data Import Module, within the 'modules/importer/importer.admin.controller.php' file.
What can an attacker potentially achieve by exploiting this SSRF vulnerability?
By manipulating the 'filename' argument, an attacker can send unauthorized requests, potentially gaining access to internal network resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.