CVE-2025-1799 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Zorlan SkyCaiji version 2.9, specifically within the previewAction function of the vendor/skycaiji/app/admin/controller/Tool.php file. This flaw allows remote attackers to manipulate the 'data' argument, potentially leading to unauthorized requests from the server. While the CVSS score is 6.3 (Medium), indicating low attack complexity and requiring low privileges, the public disclosure of the exploit code raises concerns. There is currently no evidence of active exploitation, and it lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9CPE matchmatch criteria | cpe:2.3:a:skycaiji:skycaiji:2.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.