A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-918 | |
Metrics |
cvssV3_1
|
Fri, 18 Jul 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-18T00:00:00.000Z
Updated: 2025-07-18T18:44:14.182Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52163

Updated: 2025-07-18T18:44:08.884Z

Status : Awaiting Analysis
Published: 2025-07-18T19:15:24.220
Modified: 2025-07-22T13:06:07.260
Link: CVE-2025-52163

No data.