CVE-2025-61768

KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

06 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-06 22:15

Updated : 2025-10-08 19:38


NVD link : CVE-2025-61768

Mitre link : CVE-2025-61768

CVE.ORG link : CVE-2025-61768


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-918

Server-Side Request Forgery (SSRF)