CVE-2025-10391: CRMEB OutAccountServices.php testOutUrl server-side request forgery
A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulation of the argument pushtokenurl leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10391?
CVE-2025-10391 has been assessed to have a critical severity due to the potential for server-side request forgery.
How do I fix CVE-2025-10391?
To fix CVE-2025-10391, you should upgrade CRMEB to version 5.6.2 or later.
What versions of CRMEB are affected by CVE-2025-10391?
CVE-2025-10391 affects all versions of CRMEB up to and including version 5.6.1.
What is the impact of CVE-2025-10391?
The impact of CVE-2025-10391 includes the potential for an attacker to exploit server-side request forgery vulnerabilities.
Where can I find more information about CVE-2025-10391?
More information about CVE-2025-10391 can typically be found in security advisories and vulnerability databases.