Image Editor - Moderately Critical - Server-Side Request Forgery
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-1.13
The Image Editor module fetches image URLs supplied by the user in GET/POST parameters without validating the destination host, allowing an authenticated user to cause the server to make requests to internal network resources, including cloud metadata endpoints and loopback services.