Логотип exploitDog
bind:CVE-2025-36845
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-36845

Количество 2

Количество 2

nvd логотип

CVE-2025-36845

7 месяцев назад

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-7q67-hxcf-pvj7

7 месяцев назад

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-36845

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

CVSS3: 8.6
7%
Низкий
7 месяцев назад
github логотип
GHSA-7q67-hxcf-pvj7

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

CVSS3: 8.6
7%
Низкий
7 месяцев назад

Уязвимостей на страницу