Vulnerability Details CVE-2025-27225
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.284
EPSS Ranking 96.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-27225
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:-
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.0.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.0.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.1.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.1.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.2.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.3.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.3.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.10.4.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.3.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.3.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.4.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.4.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.5.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.5.1
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.6.0
-
cpe:2.3:a:rocketsoftware:trufusion_enterprise:7.9.6.1