mccms Comic.php pic_save server-side request forgery
CVE-2023-3236
What is CVE-2023-3236?
A vulnerability has been identified in MCCMS versions up to 2.6.5, which is particularly concerning due to the function 'pic_save' within the 'Comic.php' file. This flaw allows an attacker to manipulate the 'pic' argument to execute a Server-Side Request Forgery (SSRF) attack. The severity of this vulnerability means it can be exploited remotely, posing a significant risk to affected systems, as it has already been publicly disclosed. Organizations using these versions should prioritize immediate remediation to protect their infrastructures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mccms 2.6.0
mccms 2.6.1
mccms 2.6.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
