CVE-2025-10397: Magicblack MacCMS API server-side request forgery
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10397?
CVE-2025-10397 is considered a high severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2025-10397?
To mitigate CVE-2025-10397, it is recommended to apply the latest security patches provided by Magicblack for the MacCMS software.
What type of attack is enabled by CVE-2025-10397?
CVE-2025-10397 enables a server-side request forgery (SSRF) attack which can be initiated remotely.
Which component is affected by CVE-2025-10397?
CVE-2025-10397 affects the API Handler component of the Magicblack MacCMS software.
Is the exploit for CVE-2025-10397 publicly available?
Yes, the exploit for CVE-2025-10397 is publicly available, making it crucial for users to address this vulnerability quickly.