CVE-2025-14518

MEDIUM

PowerJob < 5.1.2 - Server-Side Request Forgery via PingPongUtils checkConnectivity

Title source: llm
STIX 2.1

Description

A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.335856
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.335856
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.702896
Exploit, Issue Tracking issue-tracking
https://github.com/PowerJob/PowerJob/issues/1144
Exploit, Issue Tracking exploit issue-tracking
https://github.com/PowerJob/PowerJob/issues/1144#issue-3673393002
Various Sources product
https://github.com/PowerJob/PowerJob/

Scores

CVSS v3 6.3
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
powerjob/powerjob < 5.1.2
tech.powerjob/powerjob-common 0Maven
Published Dec 11, 2025
Tracked Since Feb 18, 2026