CVE-2025-1337 is a cross-site scripting (XSS) vulnerability in Eastnets PaymentSafe version 2.5.26.0. The issue affects an unspecified part of the BIC Search component. According to the available information, crafted input can be manipulated in a way that results in execution of attacker-controlled script in a victim's browser. The vulnerable function or exact parameter is not identified in the provided content. The issue is remotely exploitable.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a deliberately vulnerable PHP web application designed for security research and exploit development training, specifically for CVE-2025-1337 (a simulated vulnerability). The application is containerized with Docker and exposes a web interface on http://localhost:8080/. The main vulnerabilities are: - **Remote Code Execution (RCE)** via a custom template engine that executes user-supplied expressions inside `{{ ... }}` using `shell_exec` (see `dangerous_template_render` in `util.php`). This is triggered by POSTing to `/api.php?action=render_template`. - **Local File Inclusion (LFI)** via the `/api/render.php?page=...` endpoint, which includes files based on user input without validation. - **Unsafe file upload** and a web shell (`uploads/shell.php`) that allows command execution via a GET parameter. The provided exploit script (`exploit/exp.py`) automates exploitation of both RCE and LFI. The repository includes all necessary files to run the vulnerable environment (PHP source, SQL init, Docker setup) and is intended for educational use only. No real-world product is targeted; this is a training lab for understanding and practicing exploitation of RCE and LFI vulnerabilities.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-1337, a remote code execution (RCE) vulnerability in LogServ v1.2 due to insecure deserialization of the 'session_data' cookie. The repository consists of two files: a README.md describing the vulnerability and usage, and exploit.py, a Python script that crafts a malicious session cookie containing a base64-encoded payload ('uname -a') and sends it to a user-supplied target URL via an HTTP GET request. The exploit simulates the attack and does not include a real signature or advanced payload, making it a PoC. The main attack vector is network-based, targeting the web service's session handling. The script requires the attacker to specify the target URL and attempts to verify success based on the HTTP response code. No hardcoded endpoints are present; the target is supplied at runtime.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.