Vulnerability Description
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eveo | Urve Web Manager | 27.02.2025 |
Related Weaknesses (CWE)
References
- https://smartoffice.expert/enProduct
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-035.tExploitThird Party Advisory
FAQ
What is CVE-2025-36845?
CVE-2025-36845 is a vulnerability with a CVSS score of 8.6 (HIGH). An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to t...
How severe is CVE-2025-36845?
CVE-2025-36845 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36845?
Check the references section above for vendor advisories and patch information. Affected products include: Eveo Urve Web Manager.