VYPR

ScriptCase

by Netmake

CVEs (2)

  • CVE-2025-47227HigJul 5, 2025
    risk 0.49cvss 7.5epss 0.02

    In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request to login.php.is sufficient. An unauthenticated attacker can then bypass authentication via…

  • CVE-2025-47228MedJul 5, 2025
    risk 0.48cvss 6.7epss 0.15

    In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests.