{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-7702", "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21", "state": "PUBLISHED", "assignerShortName": "TR-CERT", "dateReserved": "2025-07-16T08:56:49.137Z", "datePublished": "2025-09-19T07:58:32.331Z", "dateUpdated": "2026-06-05T13:42:24.999Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21", "shortName": "TR-CERT", "dateUpdated": "2026-06-05T13:42:24.999Z" }, "title": "Open Redirect in PUSULA's Manageable Email Sending System", "datePublic": "2025-09-19T07:50:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-601", "description": "CWE-601 URL Redirection to Untrusted Site ('Open Redirect')", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-22", "descriptions": [ { "lang": "en", "value": "CAPEC-22 Exploiting Trust in Client" } ] } ], "affected": [ { "vendor": "Pusula Communication Information Internet Industry and Trade Ltd. Co.", "product": "Manageable Email Sending System", "versions": [ { "status": "affected", "version": "<=2025.06", "lessThan": "2025.08.06", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client.\n\nThis issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client.
This issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06.
" } ] } ], "references": [ { "url": "https://www.usom.gov.tr/bildirim/tr-25-0274", "tags": [ "government-resource", "broken-link" ] }, { "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0274", "tags": [ "government-resource" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseSeverity": "MEDIUM", "baseScore": 4.7, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" } } ], "credits": [ { "lang": "en", "value": "Emre DOĞAN", "type": "finder" } ], "source": { "defect": [ "TR-25-0274" ], "advisory": "TR-25-0274", "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 0.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2025-09-19T11:52:20.481930Z", "id": "CVE-2025-7702", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-09-19T11:53:02.860Z" } } ] } }