CVE-2025-47228 is a shell injection vulnerability in the Production Environment extension of Netmake ScriptCase through version 9.12.006 (23). According to the provided content, the flaw resides in the SSH connection settings functionality, where crafted HTTP requests can cause unsanitized input to be incorporated into shell command execution. This allows an authenticated attacker to inject and execute arbitrary system commands on the underlying host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python exploit for CVE-2025-47227 affecting ScriptCase Production Environment. The repo contains only three files: an MIT LICENSE, a README describing the vulnerability and usage, and the main exploit script cve_2025_47227.py. The script is not part of a larger exploitation framework. The exploit targets a pre-auth password reset flaw in ScriptCase's exposed login workflow. Its core logic initializes a requests session, disables TLS verification, optionally configures an HTTP/HTTPS proxy, and builds target URLs for the vulnerable login endpoint and CAPTCHA endpoint. It first performs lightweight detection by requesting /_lib/prod/lib/php/devel/iface/login.php and checking for ScriptCase-related markers such as nm_action, change_pass, secureimage.php, and other strings in the response body. For exploitation, the script ensures a valid session exists, downloads the CAPTCHA image from /_lib/prod/lib/php/devel/lib/php/secureimage.php, and stores it in a temporary local PNG file. CAPTCHA solving can be supplied manually with --captcha or attempted automatically. The visible code shows an optional integration with the OpenAI chat completions API to read the 4 uppercase letters from the CAPTCHA image when OPENAI_API_KEY is present. After obtaining the CAPTCHA text, the script submits the password reset request with an attacker-chosen password, then attempts to authenticate using the new credentials. On success, it prints the likely admin interface path /_lib/prod/lib/php/nm_ini_manager2.php for operator follow-up. Overall capability: pre-auth administrative account takeover via password reset, with post-reset login verification. The README also notes that this can be chained with CVE-2025-47228 for authenticated command injection leading to RCE, but this repository itself implements only the password-reset/account-takeover stage and not the command-injection exploit.
This repository is a small standalone Python exploit repo containing one functional exploit script, a README, and a license. The main file, cve_2025_47227.py, targets CVE-2025-47227 in ScriptCase Production Environment. According to the README and code, the vulnerability is a pre-authentication password reset flaw in the ScriptCase login workflow that allows an attacker to set the administrator password without a reset token or prior authentication, provided they can satisfy a simple 4-letter CAPTCHA. Repository structure is minimal: README.md documents the vulnerability and basic execution syntax; LICENSE is MIT; cve_2025_47227.py implements the exploit logic and CLI. The script uses argparse for command-line handling and requests for HTTP session management. It disables TLS verification warnings, supports an optional HTTP/HTTPS proxy, and maintains a session to preserve cookies such as PHPSESSID. Operational flow in the exploit is: detect the target by requesting the ScriptCase login endpoint; look for ScriptCase-specific markers in the response; obtain a valid session and download the CAPTCHA image from secureimage.php; solve the CAPTCHA either manually or through an optional OpenAI API call; submit the password reset request using the vulnerable login.php flow with nm_action=change_pass; then attempt to authenticate with the newly set password to confirm success. The script also prints the likely admin interface URL for manual follow-up access. The exploit is clearly offensive and functional rather than a detector. It does not itself deliver remote code execution, but it provides unauthorized administrative access by resetting the admin password. The README notes that this can be chained with CVE-2025-47228 for unauthenticated RCE, though that second-stage exploit is not implemented in this repository. Notable fingerprintable targets are the ScriptCase paths /_lib/prod/lib/php/devel/iface/login.php, /_lib/prod/lib/php/devel/lib/php/secureimage.php, and /_lib/prod/lib/php/nm_ini_manager2.php, plus the optional external endpoint https://api.openai.com/v1/chat/completions used for CAPTCHA OCR. Overall, this is a standalone operational web exploit for pre-auth admin password reset against vulnerable ScriptCase deployments.
This repository contains a Python exploit script (exploit.py) and a README.md describing the exploitation of two chained vulnerabilities in ScriptCase's Production Environment module: an authentication bypass (CVE-2025-47227) allowing admin password reset, and a shell injection (CVE-2025-47228) enabling remote command execution. The exploit script automates the attack chain, supporting four modes: full pre-auth RCE (password reset + command execution), password reset only, authenticated RCE only, and deployment path detection. The script interacts with the target over HTTP(S), handling captcha challenges via OCR, and injects arbitrary shell commands provided by the attacker. The README provides usage instructions, affected versions, and references. The main entry point is exploit.py, which is written in Python and leverages several third-party libraries (Pillow, pytesseract, requests, beautifulsoup4). The exploit targets ScriptCase installations with the vulnerable module, and the attack vector is network-based, requiring only HTTP(S) access to the target. Several fingerprintable endpoints are present, including login and captcha URLs specific to ScriptCase's deployment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.