Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is sufficient to resolve this issue. The patch is identified as 0e9736aa2c6d6bd3d60ff6ef9e0b4d32ce387f58. The affected component should be upgraded. | |
| Title | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery | |
| First Time appeared |
Octobercms
Octobercms octobercms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:octobercms:octobercms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Octobercms
Octobercms octobercms |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T12:48:33.093Z
Reserved: 2026-09-27T10:19:16.000Z
Link: CVE-2026-100909
Updated: 2026-09-28T12:48:27.780Z
Status : Deferred
Published: 2026-09-28T05:16:30.067
Modified: 2026-09-28T15:16:04.793
Link: CVE-2026-100909
No data.
OpenCVE Enrichment
Updated: 2026-09-28T06:00:12Z
