PT-2025-28034 · Netmaker · Netmake Scriptcase
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Netmake ScriptCase versions prior to 9.12.006 (23)
Description
The Production Environment extension contains a flaw in the administrator password reset mechanism. An unauthenticated remote attacker can bypass authentication and take over the administrator account by sending specifically crafted GET and POST requests to the 'login.php' endpoint. This issue may be chained with other flaws to achieve remote code execution (RCE), which is the ability to execute arbitrary commands on the target server.
Recommendations
Update to a version later than 9.12.006 (23).
As a temporary mitigation, implement immediate access restrictions to the production console.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netmake Scriptcase