PT-2025-44783 · Postgres+1 · Postgres+1

Published

2025-11-03

·

Updated

2025-11-08

·

CVE-2025-60785

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iceScrum versions 7.54 Pro On-prem
Description A remote code execution (RCE) issue exists in the Postgres Drivers component of iceScrum. An attacker can execute arbitrary code by using a specially crafted HTML page.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-60785

Affected Products

Postgres
Icescrum 7.54 Pro On-Prem