
Blackash-CVE-2025-4322
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

Proof-of-concept for a stored XSS vulnerability in Anchor CMS v0.12.7, demonstrating arbitrary JavaScript execution via the page description field.





For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.