CVE-2025-6142

MEDIUM

Intera InHire <= 20250530 - Server-Side Request Forgery via 29chcotoo9 Argument

Title source: llm
STIX 2.1

Description

A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument 29chcotoo9 leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.312613
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.312613
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.587665

Scores

CVSS v3 6.3
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
Intera/InHire 20250530
Published Jun 16, 2025
Tracked Since Feb 18, 2026