ended3월 24일· 1 sources

CVE-2026-32279: CVE-2026-32279: Server-Side Request Forgery in Connect-CMS External Page Migration

CVE-2026-32279: Connect-CMS 외부 페이지 마이그레이션 기능의 서버 측 요청 위조(SSRF) 취약점

Why it matters

Connect-CMS versions 1.x through 1.41.0 and 2.x through 2.41.0 contain an authenticated SSRF vulnerability (CVE-2026-32279, CVSS 6.8) in the External Page Migration feature, allowing administrators to force HTTP requests to arbitrary internal resources including cloud metadata endpoints. The fix introduces strict URL validation via UrlUtils::isGlobalHttpUrl and disables automatic redirects, available in versions 1.41.1 and 2.41.1.

1
Sources
+0
24h
Growth
170d
Active
Connect-CMSSSRFCVE-2026-32279CWE-918CVSS 6.8

Sources

Related Issues