CVE-2026-90710: taisan tarzan-cms Theme Download Function ThemeService.java openConnection server-side request forgery
A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied vector. An attacker manipulates the httpUrl argument used by the Theme Download Function.
Who is exposed?
Deployments of taisan tarzan-cms 1.0.0 are identified as affected, specifically the Theme Download Function implemented in com/tarzan/cms/modules/admin/service/biz/ThemeService.java. The available data does not state whether any configuration is required for the function to be reachable.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
Is a vendor fix available?
The project was notified through an issue report but had not responded at the time of the provided information. No patch or mitigation is identified in the data.