โ† Back to all CVEs

CVE-2025-60949

CRITICAL NVD
CVSS Score 9.1
Severity CRITICAL
Published Mar 23, 2026
Vendor unknown

Description

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

References