Blind Server-Side Request Forgery Vulnerability in InstantCMS by InstantSoft
CVE-2025-59055

4.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 September 2025

What is CVE-2025-59055?

A vulnerable point exists in InstantCMS up to version 2.17.3, where a blind Server-Side Request Forgery (SSRF) flaw allows authenticated attackers to manipulate HTTP/HTTPS requests. Through this vulnerability, attackers can target any external site or service within the network, potentially leading to local network scanning, denial-of-service attacks, and exposure of the server's real IP address if concealed behind a reverse proxy. The lack of available patches amplifies the risk, allowing attackers to overload server resources by sending numerous requests, thereby jeopardizing overall system stability.

Affected Version(s)

icms2 <= 2.17.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59055 : Blind Server-Side Request Forgery Vulnerability in InstantCMS by InstantSoft