CVE-2025-29455 Details
Description
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
A server-side request forgery (SSRF) vulnerability has been identified in Personal Management System version 1.4.65. This issue arises in the 'Travel Ideas' function, where the application allows users to upload images via URL. This functionality can be exploited by remote attackers to make web requests to arbitrary locations, potentially accessing and modifying information from internal services.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.yuque.com/morysummer/vx41bz/hfonnxwggi2kfgmw | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| personal-management-system personal management system | 1.4.65 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2025 | Initial Analysis | [email protected] |
| Apr 21, 2025 | CVE Modified | CISA-ADP |
| Apr 17, 2025 | New CVE Received | [email protected] |