CVE-2017-5518: Metalgenix Genixcms

High severity, CVSS 7.4. EPSS: 1.6% chance of exploitation in the next 30 days.

The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.

Affected products

Published 2017-01-17. Last modified 2026-06-17.