CVE-2018-14514

CRITICAL

idreamsoft iCMS V7.0.9 - Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/idreamsoft/iCMS/issues/29

Scores

CVSS v3 9.8
EPSS 0.0163
EPSS Percentile 73.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (1)
icmsdev/icms 7.0.9
Published Jul 23, 2018
Tracked Since Feb 18, 2026