procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery.This vulnerability is tracked as CVE-2026-18856. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
SOCIAL SHARE CARD GENERATOR