{"id":"CVE-2026-43936","summary":"e107: Server-Side Request Forgery (SSRF) in the remote file fetcher","details":"e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from \"Image/File URL:\" of \"From a remote location\" in \"Media Manager\" on the administrator screen. This vulnerability is fixed in 2.3.4.","aliases":["GHSA-92fr-7h4f-22pp"],"modified":"2026-08-04T11:50:57.793787938Z","published":"2026-05-26T14:51:49.317Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43936.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43936.json"},{"type":"ADVISORY","url":"https://github.com/e107inc/e107/security/advisories/GHSA-92fr-7h4f-22pp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43936"},{"type":"FIX","url":"https://github.com/e107inc/e107/commit/40b2d111"},{"type":"FIX","url":"https://github.com/e107inc/e107/commit/5f98cc9f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/e107inc/e107","events":[{"introduced":"0"},{"fixed":"009145d2ddb96407d8ed996ec0152b90254c8822"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.3.4"}]}}],"versions":["v2.3.3","v2.3.2","v2.3.1","v2.3.0","v2.3.0-rc1","v2.2.1","v2.2.0","v2.1.9","v2.1.8","v2.1.7","v2.1.6","v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.1","v2.0-beta1","v2.0alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43936.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}