Critical ScriptCase Flaws Allow Remote Code Execution and Server Takeover
ID: 7ef0f311-6138-5cd9-a06e-ebbbceacb36c
STIX ID: report--7ef0f311-6138-5cd9-a06e-ebbbceacb36c
Feed Name: Cyber Press
**ScriptCase prod console critical vulnerabilities (CVE-2025-47227 / CVE-2025-47228):** Researchers disclosed an authentication bypass in the password reset flow and a command-injection in the SSH local port forwarding feature that can be chained to achieve remote code execution as the web server user; a PoC script (with OCR-based CAPTCHA solving) automates the attack and impacted versions include Production Environment 1.0.003-build-2 and likely earlier releases, enabling full prod console compromise and credential leakage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
