<?xml version='1.0' encoding='utf-8'?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <title>faydin.blog – Security Research</title>
  <id>https://www.faydin.blog/en/</id>
  <link href="https://www.faydin.blog/en/feed.xml" rel="self" type="application/atom+xml" />
  <link href="https://www.faydin.blog/en/" rel="alternate" type="text/html" />
  <updated>2026-10-08T00:00:00Z</updated>
  <author>
    <name>Ferat Aydin</name>
  </author>
  <link rel="alternate" hreflang="de-AT" href="https://www.faydin.blog/feed.xml" type="application/atom+xml" />
  <link rel="alternate" hreflang="en" href="https://www.faydin.blog/en/feed.xml" type="application/atom+xml" />
  <entry>
    <title>CVE-2026-79363: Stored XSS in the branding footer</title>
    <id>https://www.faydin.blog/en/cves/CVE-2026-79363/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2026-79363/" rel="alternate" type="text/html" />
    <published>2026-10-06T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">Cloudron’s branding footer allowed HTML to be stored persistently. In the versions I tested (9.1.7 and 9.2), the value was rendered as HTML on the public login / OpenID interaction page and in the event log without sufficient sanitization. This allowed stored JavaScript to execute within the Cloudron origin.</summary>
  </entry>
  <entry>
    <title>Passive exposure analysis: Austrian organizations in a DORA-relevant environment</title>
    <id>https://www.faydin.blog/en/publikationen/passive-exposure-analyse-dora/</id>
    <link href="https://www.faydin.blog/en/publikationen/passive-exposure-analyse-dora/" rel="alternate" type="text/html" />
    <published>2026-02-09T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">I wanted to understand what passive data alone can reveal about the external attack surface of organizations operating in a DORA-relevant environment. To explore this, I examined 195 Austrian domains using Certificate Transparency and DNS data—without active scanning.</summary>
  </entry>
  <entry>
    <title>CVE-2025-60917: XSS via color input fields in /overview/network/</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-60917/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-60917/" rel="alternate" type="text/html" />
    <published>2025-11-24T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">In the OpenAtlas network overview, the color parameter could reach rendered output in a way that executed JavaScript. A crafted link was sufficient; the payload did not have to be stored.</summary>
  </entry>
  <entry>
    <title>CVE-2025-60916: Unfiltered charge parameter in /overview/network/ – DOM-based XSS</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-60916/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-60916/" rel="alternate" type="text/html" />
    <published>2025-11-24T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">The same network overview contained a second XSS vector through the charge parameter. Client-side processing could turn this data into executable content.</summary>
  </entry>
  <entry>
    <title>CVE-2025-60915: Authenticated local file inclusion (LFI) and configuration file exposure</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-60915/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-60915/" rel="alternate" type="text/html" />
    <published>2025-11-24T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">In OpenAtlas, the size parameter influenced the directory path used by a file endpoint. A low-privileged user could escape the intended directory and access files outside the uploads area.</summary>
  </entry>
  <entry>
    <title>CVE-2025-60914: Unauthorized file access (IDOR) through /display_logo</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-60914/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-60914/" rel="alternate" type="text/html" />
    <published>2025-11-24T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">The /display_logo endpoint served files from the uploads directory without properly checking authorization. Anyone who knew or could guess a valid filename could retrieve a file without logging in.</summary>
  </entry>
  <entry>
    <title>CVE-2025-56423: Username enumeration via distinct login error messages</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-56423/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-56423/" rel="alternate" type="text/html" />
    <published>2025-11-24T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">The OpenAtlas login form revealed whether a username existed by returning different error messages. This allowed valid accounts to be enumerated without knowing any passwords.</summary>
  </entry>
  <entry>
    <title>CVE-2025-51533: Predictable URL IDs expose internal forms without authorization</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-51533/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-51533/" rel="alternate" type="text/html" />
    <published>2025-08-07T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">Internal Sage DPW forms could be discovered systematically using predictable resource IDs. This became a security issue when the discovered pages lacked effective server-side authentication or authorization checks.</summary>
  </entry>
  <entry>
    <title>CVE-2025-51532: Unauthenticated access to the DB Monitor admin interface</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-51532/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-51532/" rel="alternate" type="text/html" />
    <published>2025-08-06T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">The Sage DPW Database Monitor could be accessed directly without a valid session, allowing external users to inspect internal database structures and operational information.</summary>
  </entry>
  <entry>
    <title>CVE-2025-51531: XSS in the DB Monitor (tabfields)</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-51531/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-51531/" rel="alternate" type="text/html" />
    <published>2025-08-06T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">The Sage DPW DB Monitor inserted the tabfields parameter into HTML output without proper filtering. A crafted link could therefore execute JavaScript in a user’s browser.</summary>
  </entry>
  <entry>
    <title>CVE-2025-51536: Default administrator account with hard-coded credentials</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-51536/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-51536/" rel="alternate" type="text/html" />
    <published>2025-08-04T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">OpenAtlas 8.11.0 included a privileged default account with known or hard-coded credentials. If such an account remains active, an attacker needs no further exploit: the login itself provides access.</summary>
  </entry>
  <entry>
    <title>CVE-2025-51535: Unrestricted SQL console in the admin UI</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-51535/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-51535/" rel="alternate" type="text/html" />
    <published>2025-08-04T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">OpenAtlas 8.11.0 exposed an SQL console in its administrative interface, allowing privileged users to execute broad database commands. Public CVE databases classify the finding as SQL injection, whereas my original report concerned the unrestricted SQL function in the admin UI.</summary>
  </entry>
  <entry>
    <title>CVE-2025-51534: Stored nested XSS in the Delete button</title>
    <id>https://www.faydin.blog/en/cves/CVE-2025-51534/</id>
    <link href="https://www.faydin.blog/en/cves/CVE-2025-51534/" rel="alternate" type="text/html" />
    <published>2025-08-04T00:00:00Z</published>
    <updated>2026-10-08T00:00:00Z</updated>
    <summary type="text">In OpenAtlas 8.11.0, a name field allowed JavaScript to be stored persistently. The payload subsequently reappeared in the interface and could execute in another user’s browser when that record was edited or deleted.</summary>
  </entry>
</feed>
