NerdieNews@NewsNerdieDisclosure
The post warns that CVE‑2025‑60949 allows remote attackers to retrieve Census CSWeb configuration files over HTTP, potentially exposing sensitive data.
The Hacker Wire@TheHackerWireDisclosure
The post reveals a critical vulnerability (CVE-2025-60949) in Census CSWeb 8.0.1 that permits unauthenticated retrieval of sensitive configuration data via HTTP. It lacks any PoC, exploit code, active exploitation report, or patch information.
CVEFind.com@CveFindComPatch
The tweet discloses a critical vulnerability in Census CSWeb 8.0.1 that permits unauthorized access to configuration files over HTTP and recommends upgrading to 8.1.0 alpha to remediate it.
0day Signal@0dayPublishingDisclosure
CVE-2025-60949 is a path traversal vulnerability exposing database credentials, API keys, and session secrets with zero authentication, and a high CVSS score; no PoC, exploit tool, or active exploitation evidence is provided.