Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-60898

EPSS 0.05% · P16
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-60898

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 allows a remote attacker to cause the server to issue HTTP requests to attacker-controlled URLs, including internal addresses. The endpoint performs a server-side GET to a user-supplied URI without adequate allow/blocklist validation and returns a 307 redirect that can disclose internal URLs in the Location header.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Halo CMS 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Halo CMS是中国凌霞(Halo)公司的一个博客和内容管理系统。 Halo CMS 2.21版本存在安全漏洞,该漏洞源于Thumbnail via-uri端点未经验证的用户输入,可能导致服务器端请求伪造攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-60898

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-60898

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-10-29 · 13 CVEs total

CVE-2025-63622Code-Projects Online Complaint Site 安全漏洞
CVE-2025-61161Evope Collector 安全漏洞
CVE-2025-61429NCR Atleos Terminal Manager ConfigApp 安全漏洞
CVE-2025-61156ThreatFire System Monitor 安全漏洞
CVE-2024-45162Blu-Castle BCUM221E 安全漏洞
CVE-2024-45161Blu-Castle BCUM221E 安全漏洞
CVE-2025-60542TypeORM 安全漏洞
CVE-2025-60595SPH Engineering UgCS 安全漏洞
CVE-2025-61234Dataphone A920 安全漏洞
CVE-2025-57227Kingo ROOT 安全漏洞
CVE-2025-60320memoQ 安全漏洞
CVE-2025-61876Inforcer Platform 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-60898

No comments yet


Leave a comment