CVE Vulnerabilities

CVE-2025-47227

Incorrect Provision of Specified Functionality

Published: Jul 05, 2025 | Modified: Jul 07, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

Weakness

The code does not function according to its published specifications, potentially leading to incorrect usage.

Potential Mitigations

References