Server-Side Request Forgery Vulnerability in cdevroe Unmark Product
CVE-2025-10329
Key Information:
Badges
What is CVE-2025-10329?
A vulnerability exists in cdevroe's Unmark version 1.9.3, specifically affecting the /application/controllers/Marks.php file. This security issue allows an attacker to manipulate the 'url' argument, leading to potential server-side request forgery. The exploit can be executed remotely, exposing the system to unauthorized access and data leaks. Despite early disclosure attempts, there has been no response from the vendor, making it critical for users to assess their exposure and implement necessary security measures.
Affected Version(s)
unmark 1.9.0
unmark 1.9.1
unmark 1.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved