CRITICAL9.1
GHSA-gc45-j3m5-8qfq
Server-Side Request Forgery in Feehi CMS
Details
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/feehi/cms
Introduced in:
0No fixed version published yet for feehi/cms (composer). Pin to a known-safe version or switch to an alternative.