CVE-2025-47227 Information

Description

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23) the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

Reference

https://github.com/synacktiv/CVE-2025-47227_CVE-2025-47228 https://www.scriptcase.net/changelog/ https://www.synacktiv.com/advisories/scriptcase-pre-authenticated-remote-command-execution

CNNVD-202507-518 (Published: 2025-07-04)

Share on: