|
| Description: | | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers. |
|
| Impact: | | Unauthenticated attackers can access the internal_admin_contact_login.jsp endpoint to retrieve sensitive personal information including partner and contact details, which can be used for social engineering attacks or reconnaissance. |
|
| Affected OS: | | Windows, Linux, Others |
|
| Reference: | | https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt
|
|