Home

Description

Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information. Exploitation can occur if Anonymous access is enabled, or if there is a successful CSRF attack.

PUBLISHED Reserved 2025-05-03 | Published 2025-05-03 | Updated 2025-05-05 | Assigner mitre




HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Problem types

CWE-288 Authentication Bypass Using an Alternate Path or Channel

Product status

Default status
unknown

5 (custom)
affected

References

seclists.org/fulldisclosure/2025/Apr/30

forums.inedo.com

docs.inedo.com/docs/proget/installation/installation-guide

my.inedo.com/downloads/installers?product=ProGet

cve.org (CVE-2025-47244)

nvd.nist.gov (CVE-2025-47244)

Download JSON