PT-2025-12335 · Inflectra · Inflectra Spirateam

Published

2025-03-20

·

Updated

2025-03-22

·

CVE-2024-48590

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Inflectra SpiraTeam version 7.2.00
Description The issue allows an attacker to perform Server-Side Request Forgery (SSRF) via the NewsReaderService, enabling them to escalate privileges and obtain sensitive information.
Recommendations For Inflectra SpiraTeam version 7.2.00, consider disabling the NewsReaderService as a temporary workaround until a patch is available. Restrict access to sensitive information and privileges to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48590

Affected Products

Inflectra Spirateam