TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.
References
| Link | Resource |
|---|---|
| https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt | Third Party Advisory Exploit |
| https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/ | Third Party Advisory Exploit |
| https://www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprise | Product |
| https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt | Third Party Advisory Exploit |
Configurations
History
31 Oct 2025, 20:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Rocketsoftware trufusion Enterprise
Rocketsoftware |
|
| CPE | cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:* | |
| References | () https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt - Third Party Advisory, Exploit | |
| References | () https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/ - Third Party Advisory, Exploit | |
| References | () https://www.rocketsoftware.com/products/rocket-b2b-supply-chain-integration/rocket-trufusion-enterprise - Product |
27 Oct 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-200 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/MrTuxracer/advisories/blob/master/CVEs/CVE-2025-27225.txt - |
27 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 17:15
Updated : 2025-10-31 20:33
NVD link : CVE-2025-27225
Mitre link : CVE-2025-27225
CVE.ORG link : CVE-2025-27225
JSON object : View
Products Affected
rocketsoftware
- trufusion_enterprise
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
