CVE-2025-60947Disclosure(csprousers / csweb)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch csprousers csweb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • csweb

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
csweb

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-23: 2Patch / Workaround · 2026-03-23: 2Technical Details · 2026-03-23: 203-23
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-60947 - High Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha. https://www.thehackerwire.com/vulnerability/CVE-2025-60947/ https://t.co/r6PyFJFP9Q

    Post summary

    CVE‑2025‑60947 allows authenticated file upload in Census CSWeb 8.0.1, posing a remote code execution risk, and has been mitigated in version 8.1.0 alpha.

    10000116
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-60947: HIGH] Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha.#cve,CVE-2025-60947,#cybersecurity https://cvefind.com/CVE-2025-60947

    Post summary

    A new high‑severity file‑upload vulnerability (CVE‑2025‑60947) in Census CSWeb 8.0.1 has been disclosed, with a fix available in the upcoming 8.1.0 alpha release.

    0000074
    606 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcsprouserscsweb8.0.1--

Explore more