PT-2025-37404 · Unknown · Miurla Morphic

0X1F

·

Published

2025-09-14

·

Updated

2025-09-14

·

CVE-2025-10393

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions miurla morphic versions prior to 0.4.5
Description A flaw has been found in miurla morphic. This impacts the fetchHtml function of the file /api/advanced-search of the component HTTP Status Code 3xx Handler, causing server-side request forgery. The attack is possible to be carried out remotely.
Recommendations Update miurla morphic to a version later than 0.4.5. As a temporary workaround, consider restricting access to the /api/advanced-search endpoint.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-10393

Affected Products

Miurla Morphic