Vulnerability Details CVE-2022-25026
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.056
EPSS Ranking 90.0%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-25026
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:-
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.3.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.3.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.4.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.4.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.5.0