What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in Ronald Huereca Comment Edit Core – Simple Comment Editing simple-comment-editing allows Server Side Request Forgery.This issue affects Comment Edit Core – Simple Comment Editing: from n/a through <= 3.0.33.
Explanation of Vulnerability in Simple Terms
02Summary
Comment Edit Core allows high-privilege users to make the site send HTTP requests to internal or external systems on the attacker's behalf. An attacker with admin or equivalent access can craft requests that leak sensitive data or interact with services the site can reach. The vulnerability requires high privileges and complex attack setup, limiting its practical impact.
What an attacker can do
03Attacker Capabilities
Make the site send HTTP requests to internal systems or external URLs to read data or trigger actions.
Potential impact on your site
04Site Impact
A compromised admin account could be used to access internal services, leak configuration data, or attack other systems on your network.
Conditions required to exploit
05Prerequisites
Attacker must have high-level site privileges (admin or equivalent); no user interaction required.
Key dates
06Disclosure timeline
January 24, 2025
CVE published
April 28, 2026
Record updated