Raytha CMS Server-Side Request Forgery Vulnerability in Themes Import Feature
Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Raytha CMS versions prior to 1.4.6. The issue arises in the 'Themes - Import from URL' feature, where an attacker with high privileges can manipulate server-side HTTP requests by providing a malicious URL. This vulnerability could potentially be exploited to access internal resources or perform actions on behalf of the server.
Impact
Exploitation of this vulnerability allows for Server-Side Request Forgery, where an attacker can make the server perform HTTP requests to arbitrary locations, potentially leading to the exposure of sensitive information or internal resources.
Remediation
Users can upgrade to Raytha CMS version 1.4.6 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
