CVE-2025-22374
Last modified
CVE-2025-22374 is a medium-severity vulnerability rated 6/10 on the CVSS scale. A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1.1.3. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAudit-Web, affecting versions prior to 1.1.3. This vulnerability has been patched in versions after 1.1.3. Leaving this vulnerability unpatched could lead to unauthorized access to the underlying infrastructure.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-22374?
How severe is CVE-2025-22374?
How do I fix CVE-2025-22374?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-22369The ReadFile endpoint of the firmware for Mennekes Smart / P…7.1
- CVE-2025-2237The WP RealEstate plugin for WordPress, used by the Homeo th…9.8
- CVE-2025-22370Many fields for the web configuration interface of the firmw…5.3
- CVE-2025-22371Improper Neutralization of Special Elements used in an SQL C…9.3
- CVE-2025-22372Insufficiently Protected Credentials vulnerability in Sicomm…9.3
- CVE-2025-22373Improper Neutralization of Input During Web Page Generation …8.7
- CVE-2025-22375An authentication bypass vulnerability was found in Videx's …9.3
- CVE-2025-22376In Net::OAuth::Client in the Net::OAuth package before 0.29 …5.3
- CVE-2025-22377An issue was discovered in Samsung Mobile Processor, Wearabl…6.5
- CVE-2025-2238The Vikinger theme for WordPress is vulnerable to privilege …8.8
- CVE-2025-22381Aggie 2.6.1 has a Host Header injection vulnerability in the…8.2
- CVE-2025-22383An issue was discovered in Optimizely Configured Commerce be…4.6
Are you affected by CVE-2025-22374?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
