
CVE-2025-68723
Axigen WebAdmin Stored XSS Vulnerabilities
exploitationpenetration-testingprivilege-escalation+3

Axigen WebAdmin Stored XSS Vulnerabilities
Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Crystal, Python,…

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

Stored XSS in Nagios Log Server 2024R1.3.1

Authenticated stored XSS priv esc PoC. Affects Genealogy versions prior to 4.4.0