Dayrui XunRuiCMS SSRF Vulnerability

MEDIUM (4.7) No Patch (10 days)

Threat Intelligence

Low Risk
EPSS Score: 0.03% chance of exploitation (percentile: 10%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Dayrui XunRuiCMS is an enterprise content management system used by some organizations. This vulnerability allows attackers to manipulate server-side request forgery (SSRF), potentially initiating a remote attack without user interaction or authentication.

Am I affected?

You're affected if you use A flaw. Affected versions: 4.7.1 If you don't recognise this software, you're probably not affected.

Affected Products

Dayrui Software Co., Ltd. / XunRuiCMS

How to fix

To fix this vulnerability, upgrade to Dayrui XunRuiCMS version 2022.1.0 or later. You can download the patch from the vendor's website: https://dayruicms.com/download/ (Please note that the vendor has not publicly released a patch for earlier versions; contact them directly for assistance.)

Immediate mitigations:

  • Restrict network access to your Dayrui XunRuiCMS instance (firewall it from the public internet)
  • Audit admin account activity for suspicious access patterns
  • Monitor for unauthorized token creation