CVE-2025-10395: Magicblack MacCMS Scheduled Task col_url server-side request forgery
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function colurl of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the attack remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10395?
CVE-2025-10395 has been classified as a high-severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2025-10395?
To fix CVE-2025-10395, it is recommended to update Magicblack MacCMS to the latest version that addresses the vulnerability.
What is the impact of CVE-2025-10395?
The impact of CVE-2025-10395 allows an attacker to manipulate the cjurl argument, potentially leading to unauthorized server requests.
Which component is affected by CVE-2025-10395?
The function col_url of the Scheduled Task Handler component in Magicblack MacCMS is affected by CVE-2025-10395.
Is CVE-2025-10395 exploitable remotely?
Yes, CVE-2025-10395 is exploitable remotely, allowing attackers to perform server-side request forgery attacks.