PT-2025-32222 · Bottinelli Informatical · Vedo Suite

·

CVE-2025-51058

·

Published

2025-08-06

·

Updated

2025-08-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bottinelli Informatical Vedo Suite version 2024.17
Description Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api vedo/video/preview endpoint. This allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the file URL parameter.
Recommendations Restrict access to the /api vedo/video/preview endpoint. Sanitize or validate the file URL parameter to prevent requests to arbitrary remote paths.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-51058

Affected Products

Vedo Suite