CVE-2025-28090
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-28090 is a newly discovered vulnerability affecting maccms10 v2025.1000.4047. This issue permits Server-Side Request Forgery (SSRF) attacks in the Collection Custom Interface feature. An attacker can exploit this vulnerability by manipulating network traffic to make the server issue requests to arbitrary external endpoints, potentially leading to unauthorized data leakage or server misconfiguration. Successful exploitation could result in significant security implications, including information disclosure or even complete system takeover. It is recommended that users update their maccms10 software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.