Maccms10 Server-Side Request Forgery Vulnerability in Scheduled Task Function
Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Maccms10 version 2025.1000.4047. This vulnerability arises within the Scheduled Task function, allowing attackers to manipulate request parameters and potentially access internal resources or services.
Impact
Exploitation of this vulnerability allows for Server-Side Request Forgery, where an attacker can send crafted requests from the server to internal or external resources, potentially leading to unauthorized data access or interaction with internal services.
Reproduction
To reproduce this vulnerability, upload a scheduled task and modify the request parameters to include a Burp Suite Collaborator address. Once the task is executed or tested, the Collaborator will receive the request, indicating successful exploitation.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
