Eveo URVE Web Manager 27.02.2025 contains a server-side request forgery caused by improper validation of URL input in /_internal/redirect.php, letting attackers make requests to internal endpoints, exploit requires crafted URL input.
id: CVE-2025-36845
info:
name: Eveo URVE Web Manager - Server-Side Request Forgery
author: Dhiy
...