Server-Side Request Forgery in ShopXO Product by Morysummer
CVE-2025-28093

6.3MEDIUM

Key Information:

Vendor

Morysummer

Status
Vendor
CVE Published:
28 March 2025

What is CVE-2025-28093?

The ShopXO v6.4.0 application is prone to Server-Side Request Forgery (SSRF) vulnerabilities due to improper handling of Email Settings. When exploited, this allows attackers to send unauthorized requests from the server, potentially accessing internal resources and sensitive information. It is crucial for users to apply necessary security measures to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-28093 : Server-Side Request Forgery in ShopXO Product by Morysummer