PoC Archive PoC Archive

tag

Cookie-Forgery

  • CVE-2025-5947 web CRITICAL 9.8

    WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)

    The Service Finder Bookings WordPress plugin implements a "switch back to original user" feature (intended for admin-to-user account switching) via the servicefinderswitchback() AJAX handler, registered under the servicefinderswitchback action. This handler…

    Unverified 2026-07-06
  • CVE-2025-59390 crypto CRITICAL 9.8

    Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)

    When Apache Druid's Kerberos authenticator is deployed without an explicit druid.auth.authenticator.kerberos.cookieSignatureSecret, Druid falls back to generating that secret using Java's ThreadLocalRandom, which is not cryptographically secure. Because…

    Patched 2026-07-06
  • CVE-2026-0257 web HIGH 7.8 KEV Ransomware EPSS 94%

    PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)

    CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of PAN-OS. In configurations where the same TLS certificate is reused for both the HTTPS service and the authentication-override cookie's encryption/decryption, an…

    Unverified 2026-07-01