CVE-2025-10393 Details
Description
A flaw has been found in miurla morphic up to 0.4.5. This impacts the function fetchHtml of the file /api/advanced-search of the component HTTP Status Code 3xx Handler. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.
A server-side request forgery (SSRF) vulnerability has been identified in Miurla Morphic versions through 0.4.5. The issue arises in the 'fetchHtml' function within the '/api/advanced-search' endpoint, specifically related to the HTTP Status Code 3xx Handler component. This vulnerability allows remote exploitation by manipulating response status codes, potentially leading to unauthorized access of internal services, port detection, and even causing a denial-of-service condition by repeatedly accessing specified sites.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2025CISA-ADP
Assessed Sep 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/miurla/morphic/issues/670 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.323828 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?id.323828 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.645509 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| miurla morphic | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Sep 14, 2025 | New CVE Received | [email protected] |
Volerion