CVE-2025-54122Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager Desktop and Server edition versions up to and including 25.7.18.2519. This vulnerability allows an unauthenticated attacker to bypass network isolation and access restrictions, potentially enabling access to internal services, cloud metadata endpoints, and exfiltration of sensitive data from isolated network segments. This vulnerability is fixed in version 25.7.21.2525.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-18: 1Mentions · 2026-07-21: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 1Technical Details · 2026-07-21: 103-1807-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets4 URLs
Full discourse2 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2025-54122: Manager-io/Manager allows unauthenticated full read server-side request forgery in "proxy" endpoint Critical Vulnerability Alert! OpenSSL is affected by CVE-2025-54122. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2025-54122 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2025-54122" Search Dork: app="OpenSSL" Exposure: 17.1m instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJPcGVuU1NMIg==&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260721 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces CVE-2025-54122 as a critical SSRF vulnerability in Manager-io/Manager, provides a link to detailed analysis, but offers no PoC, exploit code, mitigation, or active exploitation evidence.

    111033112.9K
    12.7K followersView on X
  • yousukezan@yousukezan
    Disclosure

    会計ソフトhttp://Manager.ioに未認証で内部ネットワークへ侵入可能な致命的欠陥が見つかり、クラウド環境の認証情報流出や乗っ取りにつながる恐れがある。攻撃は極めて容易で影響範囲も広い。 CVE-2025-54122はManager DesktopおよびServer版25.7.18.2519までに影響するSSRFで、CVSSは最大の10を記録した。原因はプロキシ処理の不備で、細工されたPOSTリクエストに含まれるリダイレクト処理を適切に検証できない点にある。攻撃者はこれを利用し、内部アドレスやクラウドのメタデータサービスへアクセスさせることが可能となる。さらにリダイレクト時にPOSTがGETへ変換される仕様を突き、POST限定の保護を回避して任意の内部リソース取得が成立する。結果としてIAM認証情報やトークン、設定ファイルなどの機密情報が外部へ送信される恐れがある。通信は正規サーバーから発生するため防御も困難であり、修正版25.7.21.2525への更新が必要とされる。 https://securityonline.info/critical-manager-io-flaw-cve-2025-54122-cvss-10-0-allows-unauthenticated-ssrf-cloud-takeover/

    Post summary

    The post discloses a severe unauthenticated SSRF flaw (CVE‑2025‑54122) in Manager.io with a CVSS of 10, details its exploitation method, and advises updating to version 25.7.21.2525, with no evidence of current wild exploitation.

    0201352.8K
    12.0K followersView on X

Explore more