CVE-2025-27225
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.
7.5
CVSS
17.2%
EPSS (exploit prob.)
97th
EPSS percentile
2025-10-27
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| rocketsoftware | trufusion_enterprise | <= 7.10.4.0 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt
- https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/
- https://www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprise
- https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-27225