{"id":"CVE-2026-36469","published":"2026-09-21T16:17:07.843","lastModified":"2026-09-24T13:17:09.750","description":"CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's \"Upload by URL\" functionality).","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://github.com/CuteNews/cutenews-2.0","tags":[]},{"url":"https://github.com/CuteNews/cutenews-2.0/blob/master/core/modules/media.php","tags":[]},{"url":"https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure","tags":[]}],"exploitRefs":[{"url":"https://github.com/CuteNews/cutenews-2.0","tags":[]},{"url":"https://github.com/CuteNews/cutenews-2.0/blob/master/core/modules/media.php","tags":[]},{"url":"https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure","tags":[]}],"hasPoc":true,"ai":{"summary":"CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) allowing attackers to forge requests and potentially access internal services or networks.","exploitability":"Exploitation requires the attacker to have the ability to trigger the 'Upload by URL' functionality, which may be difficult if the feature is not commonly used or restricted.","blast_radius":"If exploited, attackers could gain access to internal services or networks, leading to significant data exposure or system compromise.","remediation":"Upgrade to a version of CuteNews that addresses this vulnerability, such as 2.1.3 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["ssrf","web","upload","vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:05:44.582Z"}}