PT-2025-28034 · Netmaker · Netmake Scriptcase
Alexandre Droullé
+1
·
Published
2025-07-04
·
Updated
2026-06-01
·
CVE-2025-47227
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Netmake ScriptCase versions prior to 9.12.006 (23)
Description
The Production Environment extension contains a flaw in the administrator password reset mechanism. An unauthenticated remote attacker can bypass authentication and take over the administrator account by sending specifically crafted GET and POST requests to the 'login.php' endpoint. This issue may be chained with other flaws to achieve remote code execution (RCE), which is the ability to execute arbitrary commands on the target server.
Recommendations
Update to a version later than 9.12.006 (23).
Restrict access to the production console to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netmake Scriptcase