CVE-2025-47227 Information
Jul 06, 2025
cve
Description
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23) the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.
Reference
https://github.com/synacktiv/CVE-2025-47227_CVE-2025-47228 https://www.scriptcase.net/changelog/ https://www.synacktiv.com/advisories/scriptcase-pre-authenticated-remote-command-execution
Related CNNVD
CNNVD-202507-518 (Published: 2025-07-04)
Share on: