Description
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
8.0.1 (custom) before 8.1.0 alpha
8.1.0 alpha
References
github.com/hx381/cspro-exploits (url)
github.com/...ommit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91 (url)
www.cve.org/CVERecord?id=CVE-2025-60949 (url)
raw.githubusercontent.com/...IT/white/2026/va-26-082-01.json (url)