CVE-2025-51058
EUVD-2025-2388606.08.2025, 21:15
Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests towards arbitrary remote paths via the "file" URL parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vedo_suite_project | vedo_suite | 2024.17 |
𝑥
= Vulnerable software versions