CVE-2025-27225: Infoleak
Published Oct 27, 2025
·Updated
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internaladmincontactlogin.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.
Affected Software
2 affected components
TRUfusion Enterprise<7.10.4.0
Rocketsoftware Trufusion Enterprise<=7.10.4.0
Event History
Oct 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27225?
CVE-2025-27225 is a critical vulnerability that allows unauthenticated access to sensitive internal information.
2
How do I fix CVE-2025-27225?
To fix CVE-2025-27225, you should update TRUfusion Enterprise to version 7.10.4.1 or later.
3
What type of information is exposed by CVE-2025-27225?
CVE-2025-27225 exposes sensitive internal information including Personally Identifiable Information (PII).
4
Who is affected by CVE-2025-27225?
CVE-2025-27225 affects users of TRUfusion Enterprise versions up to and including 7.10.4.0.
5
What can attackers do with CVE-2025-27225?
Attackers can exploit CVE-2025-27225 to gain unauthorized access and retrieve sensitive information.