CVE-2025-60947

8.8

Census · CSWeb

Census CSWeb 8.0.1 is vulnerable to an unrestricted file upload flaw, which may allow an authenticated remote attacker to achieve remote code execution.

Executive summary

A critical file upload vulnerability in Census CSWeb allows authenticated attackers to execute arbitrary code, posing a severe risk to system integrity.

Vulnerability

The application fails to properly restrict the types of files that can be uploaded, allowing an authenticated attacker to upload malicious files to the server. This can lead to remote code execution when the uploaded file is processed or executed by the host system.

Business impact

The ability for an attacker to execute arbitrary code on the server represents a total compromise of the application environment. Given the high CVSS score of 8.8, this flaw could lead to full unauthorized access to sensitive data, potential lateral movement within the network, and significant disruption to business operations.

Remediation

Immediate Action: Update Census CSWeb to version 8.1.0 alpha or newer to remediate the underlying file upload restriction flaw.

Proactive Monitoring: Monitor web server directories for the presence of unexpected files or scripts and review access logs for suspicious file upload activity by authenticated users.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter and block file uploads containing executable extensions or suspicious content signatures.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the research referenced in the vulnerability record and the GitHub repository linked in the provided documentation.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, as it allows for complete system takeover by an authenticated user. Organizations utilizing Census CSWeb should prioritize upgrading to the fixed version 8.1.0 alpha immediately to eliminate the risk of remote code execution.

More Census CVEs

Sources