Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stefan Krause

Researcher fromSySS GmbH
#14691of 53,635
18.4Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2025-30318
9.8
2025-07-21
Unknown · Eveo Urve Web Manager · CVE-2025-36846
**Name of the Vulnerable Software and Affected Versions** Eveo URVE Web Manager version 27.02.2025 **Description** The application exposes the `/ internal/pc/vpro.php` endpoint to unauthenticated users, which is vulnerable to OS Command Injection. The endpoint accepts an input parameter that is directly passed into the `shell exec()` function of PHP. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2025-30326
8.6
2025-07-21
Eveo · Eveo Urve Web Manager · CVE-2025-36845
**Name of the Vulnerable Software and Affected Versions** Eveo URVE Web Manager version 27.02.2025 **Description** An issue exists in Eveo URVE Web Manager that allows for Server-Side Request Forgery (SSRF). The `/ internal/redirect.php` endpoint accepts a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only accessible by the application server. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.