PT-2025-28034 · Netmaker · Netmake Scriptcase

Alexandre Droullé

+1

·

Published

2025-07-04

·

Updated

2026-06-01

·

CVE-2025-47227

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Netmake ScriptCase versions prior to 9.12.006 (23)
Description The Production Environment extension contains a flaw in the administrator password reset mechanism. An unauthenticated remote attacker can bypass authentication and take over the administrator account by sending specifically crafted GET and POST requests to the 'login.php' endpoint. This issue may be chained with other flaws to achieve remote code execution (RCE), which is the ability to execute arbitrary commands on the target server.
Recommendations Update to a version later than 9.12.006 (23). Restrict access to the production console to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2026-02480
BDU:2026-02481
CVE-2025-47227

Affected Products

Netmake Scriptcase