Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BMC Software, Inc. | FootPrints | 20.20.02 ~ 20.24.01.001 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | BMC FootPrints versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability in the password reset functionality. Unauthenticated attackers can access the /footprints/servicedesk/passwordreset/request/ endpoint to obtain a valid SEC_TOKEN session cookie without proper authentication. This vulnerability enables exploitation of other vulnerabilities in the chain including CVE-2025-71258 and CVE-2025-71259 (SSRF) and CVE-2025-71260 (deserialization RCE). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-71257.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet