Zum Hauptinhalt springen
•
Apple iOS & macOSApple SouthGate Reopens Just In Time For The iPhone Duo Launch(05.10.2026 um 07:48 Uhr)
•
Android Tipps & SecurityErste Details zum Google Pixel 12 durchgesickert(05.10.2026 um 09:34 Uhr)
•
Android Tipps & SecurityBrompton zeigt 8K-LED-Prozessor Tessera SQ200 auf der leat con(05.10.2026 um 08:15 Uhr)
•
Android Tipps & SecurityLightware zeigt USB-Grenzen des MacBook Neo auf(05.10.2026 um 08:25 Uhr)
•
Android Tipps & SecurityCollaboration-Lösung IntelliMix Bar Pro von Shure verfügbar(05.10.2026 um 08:26 Uhr)
•
Android Tipps & SecurityLD Systems vernetzt historische Villa Eloise bei Rom(05.10.2026 um 08:30 Uhr)
•
Android Tipps & SecurityMonacor zeigt Dante-Matrix, DSP-Verstärker und EN-54-24-Lautsprecher(05.10.2026 um 08:35 Uhr)
••••
Apple iOS & macOSApple SouthGate Reopens Just In Time For The iPhone Duo Launch(05.10.2026 um 07:48 Uhr)
•
Android Tipps & SecurityErste Details zum Google Pixel 12 durchgesickert(05.10.2026 um 09:34 Uhr)
•
Android Tipps & SecurityBrompton zeigt 8K-LED-Prozessor Tessera SQ200 auf der leat con(05.10.2026 um 08:15 Uhr)
•
Android Tipps & SecurityLightware zeigt USB-Grenzen des MacBook Neo auf(05.10.2026 um 08:25 Uhr)
•
Android Tipps & SecurityCollaboration-Lösung IntelliMix Bar Pro von Shure verfügbar(05.10.2026 um 08:26 Uhr)
•
Android Tipps & SecurityLD Systems vernetzt historische Villa Eloise bei Rom(05.10.2026 um 08:30 Uhr)
•
Android Tipps & SecurityMonacor zeigt Dante-Matrix, DSP-Verstärker und EN-54-24-Lautsprecher(05.10.2026 um 08:35 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

CVE-2025-58011 | Alex Content Mask Plugin up to 1.8.5.2 on WordPress server-side request forgery

A vulnerability, which was classified as critical, has been found in Alex Content Mask Plugin up to 1.8.5.2 on WordPress. This affects an unknown part. This…

Beitrag
0
Seite
0
↗ Quelle (VulDB Updates)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

A vulnerability, which was classified as critical, has been found in Alex Content Mask Plugin up to 1.8.5.2 on WordPress. This affects an unknown part. This manipulation causes server-side request forgery. The identification of this vulnerability is CVE-2025-58011. It is possible to initiate the attack remotely. There is no exploit available. Weiterlesen: CVE-2025-58011 | Alex Content Mask Plugin up to 1.8.5.2 on WordPress …

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
2 Indikatoren · Defanged · STIX 2.1
CVE-2025-580111[.]8[.]5[.]2
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
4 Knoten · 3 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
CVE-2025-58011
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
ELEVATED · Index 35/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
0-Click
Authentifizierung
Erforderlich

CWE-Schwachstellen-Taxonomie & Defensive Architektur

Schwachstellen-Klassen · Root Cause · Mitigation
MITRE CWE Matrix
CWE-918 Server-Side Request Forgery (SSRF)
A10:2021-Server-Side Request Forgery
Wurzelursache (Root Cause)
Server ruft externe URLs ab, die von Nutzern übergeben wurden, ohne interne IP-Bereiche zu blockieren.
Exploitation-Mechanik
Zugriff auf Cloud-Metadatendienste (169.254.169.254), interne Kubernetes-Cluster oder Intranet-Services.
Defensive Architektur
Egress-Whitelisting, Sperren privater IP-Bereiche (RFC 1918) und Deaktivieren von HTTP-Redirects in cURL.

Compliance, SLA & Vendor Adherence

Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 6.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Impact: 2.73 | Exploitability: 3.11
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SC
Verändert (Scope Changed)
Kann auf übergeordnete Systeme oder Hypervisor/Cloud-Ebene übergreifen (Sandbox Escape).
CL
Gering (Teilabfluss)
Teilweiser oder kein Datenabfluss.
IL
Gering (Teilweise)
Teilweise oder keine Manipulation.
AN
Keine
Teilweise oder keine Beeinträchtigung.
NVD Primärbewertung & CISA SSVCCVE-2025-58011
NVD: DeferredNVD 6.4 · MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
NVD-Datenstand: 30.09.2026, 23:10 UTC
Ausnutzung beobachtet: Nein Automatisierbar: Nein Technischer Impact: Teilweise
CISA-SSVC-Triage (vulnrichment)CVE-2025-58011
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-09-23T15:40:53.060387Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Zum Aktualisieren ziehen
Nächster Beitrag