A vulnerability classified as critical has been found in Poesis Rhymix CMS up to 2.1.33. This impacts the function
procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery.
This vulnerability is tracked as CVE-2026-18856. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.