PT-2025-53439 · Yunaiv · Yudao-Cloud

·

CVE-2025-15098

·

Published

2025-12-26

·

Updated

2025-12-26

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions YunaiV yudao-cloud versions prior to 2025.11
Description A server-side request forgery condition exists in the Business Process Management component, specifically within the BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger function. Manipulation of the url, header, or body arguments can be exploited to perform server-side request forgery attacks remotely. The exploit has been publicly disclosed, and the vendor was notified but did not respond.
Recommendations Versions prior to 2025.11 should be updated. As a temporary workaround, consider restricting access to the BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger function until a patch is available. Avoid using untrusted data in the url, header, or body parameters.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15098

Affected Products

Yudao-Cloud