Metrics
Affected Vendors & Products
Tue, 24 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 23 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of the component Meta URL Handler. The manipulation of the argument post leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Dromara MaxKey Meta URL SAML20DetailsController.java add server-side request forgery | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-23T18:00:15.580Z
Updated: 2025-06-24T13:33:50.343Z
Reserved: 2025-06-23T12:21:44.852Z
Link: CVE-2025-6517

Updated: 2025-06-24T13:33:39.251Z

Status : Awaiting Analysis
Published: 2025-06-23T18:15:22.797
Modified: 2025-06-24T14:15:31.093
Link: CVE-2025-6517

No data.