Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Tenable updates Vulnerability Priority Rating scoring method to flag fewer vulnerabilities as critical

      July 24, 2025

      Google adds updated workspace templates in Firebase Studio that leverage new Agent mode

      July 24, 2025

      AI and its impact on the developer experience, or ‘where is the joy?’

      July 23, 2025

      Google launches OSS Rebuild tool to improve trust in open source packages

      July 23, 2025

      Atomic Design Certification Course

      July 24, 2025

      How to streamline GitHub API calls in Azure Pipelines

      July 24, 2025

      Reform Collective: A New Website, Designed to Be Seen

      July 24, 2025

      Motion Highlights #11

      July 24, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The details of TC39’s last meeting

      July 24, 2025
      Recent

      The details of TC39’s last meeting

      July 24, 2025

      Building Scalable APIs with Node.js and TypeScript

      July 24, 2025

      What’s new in ECMAScript 2025

      July 24, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      How to Open Control Panel in Windows 11

      July 24, 2025
      Recent

      How to Open Control Panel in Windows 11

      July 24, 2025

      How to Shut Down Windows 11

      July 24, 2025

      What is Digital Music?

      July 24, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-46341 – FreshRSS HTTP Auth Header Impersonation Vulnerability

    CVE-2025-46341 – FreshRSS HTTP Auth Header Impersonation Vulnerability

    June 4, 2025

    CVE ID : CVE-2025-46341

    Published : June 4, 2025, 9:15 p.m. | 2 hours, 22 minutes ago

    Description : FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse proxy, it’s possible to impersonate any user either via the `Remote-User` header or the `X-WebAuth-User` header by making specially crafted requests via the add feed functionality and obtaining the CSRF token via XPath scraping. The attacker has to know the IP address of the proxied FreshRSS instance and the admin’s username, while also having an account on the instance. An attacker can send specially crafted requests in order to gain unauthorized access to internal services. This can also lead to privilege escalation like in the demonstrated scenario, although users that have setup OIDC are not affected by privilege escalation. Version 1.26.2 contains a patch for the issue.

    Severity: 7.1 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-48947 – Auth0 Next.js SDK Cache-Control Header Missing Vulnerability
    Next Article CVE-2025-5609 – Tenda AC18 Buffer Overflow Vulnerability

    Related Posts

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-54365 – Fastapi-Guard Regular Expression ReDoS Bypass

    July 24, 2025
    Development

    UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP Rootkit

    July 23, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Custom Object Casting in Laravel Models

    Development

    These are the 5 Prime Day deals I’d buy if I weren’t about to have a baby

    News & Updates

    CVE-2024-11861 – EnerSys AMPA Remote Command Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CSS Cursor Types Explained

    Web Development

    Highlights

    Security terms explained: What does Zero Day mean?

    April 9, 2025

    One of the terms I’m most often asked to explain is what a “zero day”…

    CVE-2025-7787 – Xuxueli xxl-job Server-Side Request Forgery (SSRF) Vulnerability

    July 18, 2025

    Firefox Now Lets You Add Custom Images to New Tab Page

    May 15, 2025

    The AI Fix #49: The typo from hell

    May 6, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.