Опубликовано: 24 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.1
Описание
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-60949
- https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91
- https://github.com/hx381/cspro-exploits
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json
- https://www.cve.org/CVERecord?id=CVE-2025-60949
EPSS
Процентиль: 13%
0.00043
Низкий
9.3 Critical
CVSS4
9.1 Critical
CVSS3
CVE ID
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 9.1
nvd
14 дней назад
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
EPSS
Процентиль: 13%
0.00043
Низкий
9.3 Critical
CVSS4
9.1 Critical
CVSS3
CVE ID
Дефекты
CWE-200