VulnerAlert



APPLICATION
29-10-2025 04:58
Tags
#injection
#hacker
#exploit
#critical
#list
#html
#form
#application
#vulnerability
#improper
#arbitrary
#threat
#security
#remote
#privilege
#issue
#inject
#flaw
#execution
#execute
#critic
#allow
#attack
#access
#affect
Descripción
Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack Threat actors are actively exploiting multiple security flaws impacting Systèmes DELMIA Apriso XWiki, according to alerts issued by the U.S. Cybersecurity Infrastructure Security Agency ( ) VulnCheck . The vulnerabilities listed below - CVE-2025-6204 (CVSS score: 8.0) A code injection vulnerability in that could allow an attacker execute arbitrary code. CVE-2025-6205 9.1) missing authorization gain privileged access application. CVE-2025-24893 9.8) An improper neutralization of input a dynamic evaluation call (aka eval any guest user perform remote execution through request "/bin/get/Main/SolrSearch" endpoint. Both affect versions from Release 2020 202... https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
CVE-2025-6204
CVE-2025-6205
CVE-2025-24893
Link externo
Ver detalles

Fuente
https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
Resultados similares
Coincidentes en almenos en 50% de los tags
29-10-2025 CVE-2025-31993
HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery...
Ver información
28-10-2025 CVE-2025-34317
IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vu...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por