CVE-2025-60949Disclosure(csprousers / csweb)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch csprousers csweb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • csweb

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-23); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
csweb

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-23: 3Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 3Technical Details · 2026-03-24: 103-2303-24
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-233
Disclosure2Patch1
2026-03-241
Disclosure1
Full discourse4 posts
  • NerdieNews@NewsNerdie
    Disclosure

    CVE-2025-60949: Remote attackers can access Census CSWeb configuration files via HTTP, risking sensitive data exposure. This critical vulnerability highlights the need for robust security measures in web systems. #CyberSecurity #InfoSec

    Post summary

    The post warns that CVE‑2025‑60949 allows remote attackers to retrieve Census CSWeb configuration files over HTTP, potentially exposing sensitive data.

    00000149
    50 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-60949 - Critical Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secret... https://www.thehackerwire.com/vulnerability/CVE-2025-60949/ https://t.co/6yBJ49RXv8

    Post summary

    The post reveals a critical vulnerability (CVE-2025-60949) in Census CSWeb 8.0.1 that permits unauthenticated retrieval of sensitive configuration data via HTTP. It lacks any PoC, exploit code, active exploitation report, or patch information.

    00000109
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-60949: CRITICAL] Vulnerable Census CSWeb 8.0.1 allows access to configuration files over HTTP, potentially exposing secrets. Update to secure version 8.1.0 alpha to fix this issue.#cve,CVE-2025-60949,#cybersecurity https://cvefind.com/CVE-2025-60949

    Post summary

    The tweet discloses a critical vulnerability in Census CSWeb 8.0.1 that permits unauthorized access to configuration files over HTTP and recommends upgrading to 8.1.0 alpha to remediate it.

    0000073
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-60949: Census CSWeb leaked configuratio... Direct path traversal to `/app/config` exposes database creds, API keys, and session secrets—zero-auth required, CVSS 9... https://zerodaysignal.com/vulnerability/CVE-2025-60949 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2025-60949 is a path traversal vulnerability exposing database credentials, API keys, and session secrets with zero authentication, and a high CVSS score; no PoC, exploit tool, or active exploitation evidence is provided.

    00000136
    164 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcsprouserscsweb8.0.1--

Explore more