PT-2025-30326 · Eveo · Eveo Urve Web Manager

Stefan Krause

·

Published

2025-07-21

·

Updated

2026-01-16

·

CVE-2025-36845

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eveo URVE Web Manager version 27.02.2025
Description An issue exists in Eveo URVE Web Manager that allows for Server-Side Request Forgery (SSRF). The / internal/redirect.php endpoint accepts a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only accessible by the application server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-36845

Affected Products

Eveo Urve Web Manager