Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component. | |
| Title | Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdminCheckXmlFile server-side request forgery | |
| First Time appeared |
Poesis
Poesis rhymix Cms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:poesis:rhymix_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Poesis
Poesis rhymix Cms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-05T00:30:12.143Z
Reserved: 2026-08-04T15:58:58.811Z
Link: CVE-2026-18856
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T02:30:03Z
-
CWE-918
Server-Side Request Forgery (SSRF)