CVE-2025-60785
8.8iceScrum · iceScrum Pro On-prem
A remote code execution vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows unauthenticated attackers to execute arbitrary code via a crafted HTML page.
Executive summary
The iceScrum Pro On-prem platform contains a critical remote code execution vulnerability that allows attackers to gain unauthorized control over the host system.
Vulnerability
The vulnerability exists within the Postgres Drivers component, which fails to properly sanitize input, allowing an unauthenticated attacker to trigger remote code execution by delivering a crafted HTML page.
Business impact
This vulnerability carries a CVSS score of 8.8, reflecting its high potential for system compromise. Successful exploitation grants an attacker the ability to execute arbitrary commands, which could lead to a total loss of confidentiality, integrity, and availability for the affected server and any data stored within the iceScrum environment.
Remediation
Immediate Action: Since no specific patch version is identified in the provided data, administrators should immediately restrict network access to the iceScrum instance and monitor official vendor security channels for the release of a corrective update.
Proactive Monitoring: Review web server access logs for suspicious requests containing anomalous HTML payloads or unexpected references to the Postgres Drivers component.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter out malicious or malformed HTML requests that match the attack signature associated with this vulnerability.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of remote code execution, organizations must prioritize the isolation of affected iceScrum systems from the public internet. Until an official patch is verified and applied, rely on strict network access controls and WAF filtering to mitigate the risk of exploitation.