High severity7.5NVD Advisory· Published Jan 12, 2023· Updated Jun 17, 2026
CVE-2022-25026
CVE-2022-25026
Description
A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensitive resources on the internal network via a crafted HTTP request to /trufusionPortal/upDwModuleProxy.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*Range: <7.9.5.1
- Rocket TRUfusion Portal/Rocket TRUfusion Portaldescription
- Range: = 7.9.2.1
Patches
Vulnerability mechanics
References
1- labs.nettitude.com/blog/cve-2022-25026-cve-2022-25027-vulnerabilities-in-rocket-trufusion-enterprise/nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.