<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>faydin.blog – Security Research</title>
<id>https://www.faydin.blog/</id>
<link href="https://www.faydin.blog/feed.xml" rel="self"/>
<link href="https://www.faydin.blog/"/>
<updated>2026-09-22T00:00:00Z</updated>
<author><name>Ferat Aydin</name></author>
<entry>
<title>Passive Exposure-Analyse: Organisationen in einem DORA-relevanten Umfeld in Österreich</title>
<id>https://www.faydin.blog/publikationen/passive-exposure-analyse-dora/</id>
<link href="https://www.faydin.blog/publikationen/passive-exposure-analyse-dora/"/>
<published>2026-02-09T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>Ich wollte wissen, was man über die externe Angriffsfläche von Organisationen in einem DORA-relevanten Umfeld allein mit passiven Daten sehen kann. Dafür habe ich 195 österreichische Domains mit Certificate Transparency und DNS ausgewertet – ohne aktive Scans.</summary>
</entry>
<entry>
<title>CVE-2025-60917: XSS in Farbeingabefeldern ORT (/overview/network/)</title>
<id>https://www.faydin.blog/cves/CVE-2025-60917/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-60917/"/>
<published>2025-11-24T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · XSS · betroffen &lt;= 8.12.0</summary>
</entry>
<entry>
<title>CVE-2025-60916: Ungefilterte Parameter charge im Endpunkt /overview/network/ – DOM-based XSS</title>
<id>https://www.faydin.blog/cves/CVE-2025-60916/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-60916/"/>
<published>2025-11-24T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · XSS (DOM) · betroffen &lt;= 8.12.0</summary>
</entry>
<entry>
<title>CVE-2025-60915: Authentifizierte Local File Inclusion (LFI) – Konfigurationsdatei-Exfiltration</title>
<id>https://www.faydin.blog/cves/CVE-2025-60915/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-60915/"/>
<published>2025-11-24T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · LFI / Path Traversal · betroffen &lt;= 8.12.0</summary>
</entry>
<entry>
<title>CVE-2025-60914: Unautorisierter Zugriff (IDOR) auf Dateien im Upload-Verzeichnis über /display_logo</title>
<id>https://www.faydin.blog/cves/CVE-2025-60914/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-60914/"/>
<published>2025-11-24T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · Broken Access Control (IDOR) · betroffen &lt;= 8.12.0</summary>
</entry>
<entry>
<title>CVE-2025-56423: Standard-Fehlermeldung zur Benutzerevaluierung</title>
<id>https://www.faydin.blog/cves/CVE-2025-56423/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-56423/"/>
<published>2025-11-24T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · Information Disclosure · betroffen &lt;= 8.12.0</summary>
</entry>
<entry>
<title>CVE-2025-51533: Vorhersehbare URL-IDs ermöglichen unautorisierten Zugriff auf interne Formulare</title>
<id>https://www.faydin.blog/cves/CVE-2025-51533/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-51533/"/>
<published>2025-08-07T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>Sage DPW v8 · Broken Access Control · betroffen &lt;= 2024_12_004</summary>
</entry>
<entry>
<title>CVE-2025-51532: Unauthentifizierter Zugriff Adminbereich DB-Monitor</title>
<id>https://www.faydin.blog/cves/CVE-2025-51532/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-51532/"/>
<published>2025-08-06T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>Sage DPW v8 (OnPremise) · Broken Access Control · betroffen &lt;= 2024_12_004</summary>
</entry>
<entry>
<title>CVE-2025-51531: XSS in DB-Monitor (tabfields)</title>
<id>https://www.faydin.blog/cves/CVE-2025-51531/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-51531/"/>
<published>2025-08-06T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>Sage DPW v8 · XSS · betroffen &lt;= 2024_12_004</summary>
</entry>
<entry>
<title>CVE-2025-51536: Standard-Adminkonto mit hartcodiertem Passwort</title>
<id>https://www.faydin.blog/cves/CVE-2025-51536/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-51536/"/>
<published>2025-08-04T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · Authentication / Default Credentials · betroffen &lt;= 8.11.0</summary>
</entry>
<entry>
<title>CVE-2025-51535: Unbeschränkte SQL-Konsole im Admin-UI</title>
<id>https://www.faydin.blog/cves/CVE-2025-51535/</id>
<link href="https://www.faydin.blog/cves/CVE-2025-51535/"/>
<published>2025-08-04T00:00:00Z</published>
<updated>2026-09-22T00:00:00Z</updated>
<summary>OpenAtlas · Dangerous Functionality / Misconfiguration · betroffen &lt;= 8.11.0</summary>
</entry>
</feed>
