VYPR
High severity8.6NVD Advisory· Published Jul 21, 2025· Updated Jun 17, 2026

CVE-2025-36845

CVE-2025-36845

Description

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Eveo/Urve Web Managerllm-fuzzy3 versions
    27.02.2025+ 2 more
    • (no CPE)range: 27.02.2025
    • (no CPE)
    • cpe:2.3:a:eveo:urve_web_manager:27.02.2025:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.