We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-44043



Description

Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetResults and /Keyoti_SearchEngine_Web_Common/SearchService.svc/GetLocationAndContentCategories. An attacker can specify their own SMB server as the indexDirectory value when making POST requests to the affected components. In doing so an attacker can get the SearchUnit server to read and write configuration and log files from/to the attackers server.

Reserved 2025-04-22 | Published 2025-06-10 | Updated 2025-06-10 | Assigner mitre

References

keyoti.com/...HtmlHelp9/?topic=UserGuide/Release%20Notes.htm

www.sprocketsecurity.com/...-search-bar-hacks-arent-dead-yet

cve.org (CVE-2025-44043)

nvd.nist.gov (CVE-2025-44043)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-44043

Support options

Helpdesk Chat, Email, Knowledgebase