CVE-2025-47227
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 2.05%
- CWE
- CWE-684
- Published
- 2025-07-05
- Last modified
- 2026-03-13
Affected products
- ScriptCase ScriptCase
Weakness type
Related vulnerabilities
- CVE-2026-79126 — Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to...
- CVE-2026-52735 — ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
- CVE-2026-44597 — Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a...
- CVE-2026-40685 — In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a...
- CVE-2026-40684 — In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection...
- CVE-2026-42255 — Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server...
- CVE-2026-35381 — uutils coreutils cut Local Logic Error and Data Integrity Issue in Output Filtering
- CVE-2026-35379 — uutils coreutils tr Local Logic Error and Data Integrity Issue in Character Class Handling