CVE-2025-47244

high

Description

Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information. Exploitation can occur if Anonymous access is enabled, or if there is a successful CSRF attack.

References

https://seclists.org/fulldisclosure/2025/Apr/30

https://my.inedo.com/downloads/installers?product=ProGet

https://forums.inedo.com

https://docs.inedo.com/docs/proget/installation/installation-guide

Details

Source: Mitre, NVD

Published: 2025-05-03

Updated: 2025-05-05

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity: High

EPSS

EPSS: 0.0009