TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.
References
| Link | Resource |
|---|---|
| https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt | Exploit Third Party Advisory |
| https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/ | Exploit Third Party Advisory |
| https://www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprise | Product |
| https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-10-27 17:15
Updated : 2025-10-31 20:33
NVD link : CVE-2025-27225
Mitre link : CVE-2025-27225
CVE.ORG link : CVE-2025-27225
JSON object : View
Products Affected
rocketsoftware
- trufusion_enterprise
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
