Record summary

CVE-2021-47958 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.2.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBCouchCMS 2.2.1 - Server-Side Request ForgeryExploitDB exploitby xxcddNot analyzed1 file
ExploitDB

PoC details

References

4