CVE-2021-47958

CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.
Configurations

No configuration.

History

15 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 19:16

Updated : 2026-06-17 04:18


NVD link : CVE-2021-47958

Mitre link : CVE-2021-47958

CVE.ORG link : CVE-2021-47958


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)