Security Advisory

CVE-2025-51058

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-06 00:00:00
Last updated 2025-08-07 13:37:57
Assigner mitre
State PUBLISHED

Description

Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the "file" URL parameter.