Логотип exploitDog
bind:CVE-2025-47227
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-47227

Количество 2

Количество 2

nvd логотип

CVE-2025-47227

около 1 месяца назад

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-276w-gj4p-9x23

около 1 месяца назад

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-47227

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-276w-gj4p-9x23

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу