THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-71259 (MEDIUM 4.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficien

[NVD] CVE-2025-71259 (MEDIUM 4.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficien

lownvdPublished 2026-03-19

CVE-2025-71259 CVSS: 4.3 MEDIUM Published: 2026-03-19T14:16:13.380

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficient validation of externally supplied resource referen

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71259