Server-Side Request Forgery Vulnerability in InstantCMS by InstantSoft
CVE-2026-48707
3.1LOW
What is CVE-2026-48707?
InstantCMS, an open-source content management system, has a vulnerability in its file upload feature that can be exploited to launch Server-Side Request Forgery (SSRF) attacks. Specifically, when users upload files via the 'upload from URL' option, if the process encounters an HTTP redirect, it may inadvertently bypass the blacklist checks for private IP addresses. This flaw allows authenticated users to potentially access and scan internal network services, posing a significant security risk. The issue was addressed in version 2.18.2, making it essential for users to update to this release to ensure their systems are secure.
Affected Version(s)
icms2 < 2.18.2
