CVE-2026-6649

MEDIUM

Qibo CMS headers server-side request forgery

Title source: cna
STIX 2.1

Description

A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-358283 | Qibo CMS headers server-side request forgery
https://vuldb.com/vuln/358283
Signature, Permissions Required signature permissions-required
VDB-358283 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/358283/cti
Third Party Advisory third-party-advisory
Submit #793510 | Guangzhou Qibo Network Technology Co., Ltd. Qibo CMS (x1_of_cms) X1.0 SSRF
https://vuldb.com/submit/793510

Scores

CVSS v3 6.3
EPSS 0.0021
EPSS Percentile 10.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
Qibo/CMS 1.0
Published Apr 20, 2026
Tracked Since Apr 20, 2026