PatchSiren cyber security CVE debrief
CVE-2023-1725 Infoline Tr CVE debrief
CVE-2023-1725 is a critical server-side request forgery (SSRF) issue in Infoline Project Management System affecting versions before 4.09.31.125. The vulnerability was published on 2023-03-30 and later modified on 2024-11-21. NVD records a network-reachable attack path with no privileges or user interaction required and a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high potential impact if exposed.
- Vendor
- Infoline Tr
- Product
- Project Management System
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-03-30
- Original CVE updated
- 2024-11-21
- Advisory published
- 2023-03-30
- Advisory updated
- 2024-11-21
Who should care
Administrators and security teams responsible for Infoline Project Management System deployments, especially instances running versions before 4.09.31.125. Network defenders should also pay attention if the application can make outbound web requests or reach internal services.
Technical summary
The NVD entry maps the issue to CWE-918 and lists the affected CPE as infoline-tr:project_management_system with vulnerable versions ending before 4.09.31.125. The vulnerability is described as SSRF, meaning the application can be induced to make server-side requests. NVD assigns CVSS 3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the record cites a USOM advisory as a reference.
Defensive priority
critical
Recommended defensive actions
- Upgrade Infoline Project Management System to 4.09.31.125 or later.
- Restrict and monitor outbound network access from the application server, especially to sensitive internal destinations.
- Review proxy, firewall, and application logs for suspicious server-side outbound requests around the affected period.
- Validate that any user-controlled URLs, callbacks, imports, or fetch features are tightly allowlisted and sanitized.
- Follow the linked USOM advisory and NVD record for any vendor-specific remediation guidance.
Evidence notes
Source evidence comes from the NVD CVE record and its referenced USOM advisory. The NVD metadata identifies the affected product family, version cutoff, CWE-918 classification, and CVSS vector. No known exploitation or KEV listing was supplied in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-1725 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-1725
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-1725 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-1725
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0187
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.