CVE-2026-43936 Details
Description
e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "Media Manager" on the administrator screen. This vulnerability is fixed in 2.3.4.
A server-side request forgery (SSRF) vulnerability has been identified in e107, a content management system (CMS), prior to version 2.3.4. This vulnerability allows authenticated administrators to access the local environment by specifying a URL in the 'Image/File URL' field of the 'Media Manager' on the administrator screen. The issue arises because the 'e_file::getRemoteFile()' and 'getRemoteContent()' methods previously accepted URLs without proper validation, enabling potential port scanning or access to internal services through imported media.
Users can update to e107 version 2.3.4, where this vulnerability has been patched. Instructions for this update can be found in the e107 documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/e107inc/e107/security/advisories/GHSA-92fr-7h4f-22pp | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/e107inc/e107/commit/40b2d111 | [email protected] | Source CodeVendor |
| https://github.com/e107inc/e107/commit/5f98cc9f | [email protected] | Source CodeVendor |
| https://github.com/e107inc/e107/security/advisories/GHSA-92fr-7h4f-22pp | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| e107 | <= 2.3.3 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |
Volerion