CVE-2025-28093:
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Email Settings
6.3
CVSS ScoreBasic Information
CVE ID
GHSA ID
EPSS Score
-
CWE
Published
3/29/2025
Updated
4/1/2025
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
shopxo/shopxo | composer | <= 6.4.0 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The SSRF vulnerability in email settings suggests improper validation of user-supplied URLs/hosts in SMTP configuration. Based on typical PHP application patterns:
- EmailController::save would handle form submissions for email settings
- EmailService::testConnection would execute network operations to verify SMTP credentials Without proper input sanitization in these functions, user-controlled URLs could trigger internal network requests. Confidence is medium as these are common patterns despite lack of direct patch evidence.