Product
An unauthenticated server-side request forgery (SSRF) vulnerability in OctoberCMS allows remote attackers to manipulate the realSourcePath argument to perform unauthorized internal network requests.