MEDIUM
OctoberCMS
CVE published 2026-09-28
CVE-2026-100909
A server-side request forgery vulnerability was found in OctoberCMS, specifically in the `getSourcePathForResize` function of the `ResizeImages.php` file. The vulnerability allows remote attackers to perform server-side request forgery by manipulating the `realSourcePath` argument. The exploit has been made public, and upgrading to version 4.3.5 or 4.4.0 is sufficient to resolve this issue.