← back
CVE-2025-50125

CVE-2025-50125

CVSS 6.3 MEDIUMEPSS 0.5%CWE-918
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →