CVE-2025-60949
EUVD-2025-20895423.03.2026, 22:16
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| csprousers | csweb | 8.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration