Server-Side Request Forgery Vulnerability in ControlID iDSecure
CVE-2025-49852
8.7HIGH
What is CVE-2025-49852?
The ControlID iDSecure product, specifically versions 4.7.48.0 and earlier, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows an unauthenticated attacker to send crafted requests from the server, potentially enabling unauthorized access to sensitive information hosted on other servers. Organizations using these versions should take immediate steps to secure their systems and mitigate potential risks associated with this vulnerability.
Affected Version(s)
iDSecure On-premises 0 <= 4.7.48.0