CVE-2024-25738

CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configu...

Affects 0 products across 2 vendors.

BCS7.0
CVSS 3.19.1
EPSS0.7%
Percentile49th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-918: Server-Side Request Forgery (SSRF)

Attacker causes the server to make HTTP requests to attacker-chosen destinations, potentially reaching internal services.

Related Attack Patterns (CAPEC)
CAPEC-664 Server Side Request Forgery
via CWE-918

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files, potentially gaining access to the administrator panel and achieving Remote Code Execution.

BSID: BS-2024-GLOBAL-049293-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-25738?
A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files, potentially gaining access to the administrator panel and achieving Remote Code Execution.
What is the CVSS score for CVE-2024-25738?
CVE-2024-25738 has CVSS 9.1 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. EPSS: 0.7%.
Is CVE-2024-25738 actively exploited?
No confirmed active exploitation of CVE-2024-25738 as of 2026-05-30.
How do I remediate CVE-2024-25738?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-25738?
CVE-2024-25738 affects: Files, Foundation.
Vulnerability Details
CVE IDCVE-2024-25738
BSIDBS-2024-GLOBAL-049293-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Published2024-05-22
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files to gain access to the administrator panel and achieve Remote Code Execution. A mitigating factor is that it requires the allow_url_include PHP runtime setting to be on, which is off in default installations. It also requires the /Upgrade route to be exposed, which is exposed by default after installing VuFind, and is recommended to be disabled by setting autoConfigure to false in config.ini.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the /Upgrade/FixConfig route of VuFind versions 2.0 through 9.1 before 9.1.1. An attacker can exploit this by sending a specially crafted request that leverages the SSRF vulnerability to overwrite local configuration files. This can lead to unauthorized access to the administrator panel and, under certain conditions, Remote Code Execution. The attack requires the allow_url_include PHP runtime setting to be enabled, which is off by default.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Files —
Foundation —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 794 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash222c59c4d4f1a55c899550dace4a060c6f1dca12b14f5be29f49f154324896e452278ed89b3cc8c05193b9cdb766e2cccd658bf3723c600918b18a91bc26ef20
Related CVEs affecting Files
CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-2025-48148 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper ... CVE-2026-34909 10.0 A malicious actor with access to the network could exploit a Path Traversal v... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h...
View all Files CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.1 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →