A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/controllers/Marks.php. The manipulation of the argument url results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 16 Sep 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Unmark
Unmark unmark
CPEs cpe:2.3:a:unmark:unmark:*:*:*:*:*:*:*:*
Vendors & Products Unmark
Unmark unmark

Mon, 15 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Cdevroe
Cdevroe unmark
Vendors & Products Cdevroe
Cdevroe unmark

Fri, 12 Sep 2025 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in cdevroe unmark up to 1.9.3. This affects an unknown part of the file /application/controllers/Marks.php. The manipulation of the argument url results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title cdevroe unmark Marks.php server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-12T22:02:05.529Z

Updated: 2025-09-15T15:10:52.169Z

Reserved: 2025-09-12T08:46:01.011Z

Link: CVE-2025-10329

cve-icon Vulnrichment

Updated: 2025-09-15T14:43:51.750Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-12T22:15:33.710

Modified: 2025-09-16T17:17:18.993

Link: CVE-2025-10329

cve-icon Redhat

No data.