CVE-2025-28091
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Mar 28, 2025
Updated: Apr 7, 2025
CWE ID 918
Summary
CVE-2025-28091 is a Server-Side Request Forgery (SSRF) vulnerability affecting maccms10 v2025.1000.4047. Maliciously crafted requests through the "Add Article" function can trick the server into making unintended external HTTP requests, potentially leading to data leakage or server takeover. This issue poses a significant security risk and requires immediate attention and patching from users to prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.