Description

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via administrator account takeover.

INFO

Published Date :

2025-07-05T00:00:00.000Z

Last Modified :

2025-07-07T18:35:57.991Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-47227 vulnerability.

Vendors Products
Scriptcase
  • Scriptcase
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact