<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-863 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-863/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-863/index.xml" rel="self" type="application/rss+xml"/><item><title>Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6758. Status: Weaponized. Affects: Real Spaces - Properties Directory Theme for WordPress (imic_agent_register AJAX handler). Tags: wordpress, real-spaces, imic, privilege-escalation, unauthenticated, admin-ajax, role-assignment, cwe-269, cwe-863, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>real-spaces</category><category>imic</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>role-assignment</category><category>cwe-269</category><category>cwe-863</category><category>python</category></item><item><title>FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-66039. Status: PoC. Affects: FreePBX (Sangoma) framework module — web-based administration panel for Asterisk-based VoIP/PBX systems. Tags: freepbx, sangoma, voip, telephony, authentication-bypass, access-control, authtype, webserver-auth, cwe-287, cwe-863, nuclei, version-fingerprinting.</description><category>network</category><category>Critical</category><category>freepbx</category><category>sangoma</category><category>voip</category><category>telephony</category><category>authentication-bypass</category><category>access-control</category><category>authtype</category><category>webserver-auth</category><category>cwe-287</category><category>cwe-863</category><category>nuclei</category><category>version-fingerprinting</category></item><item><title>LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-47102-litellm-privesc-user-update/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-47102-litellm-privesc-user-update/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-47102. Status: PoC. Affects: LiteLLM (LLM API proxy / gateway). Tags: litellm, privilege-escalation, broken-access-control, cwe-863, api-authorization, llm-proxy.</description><category>web</category><category>High</category><category>litellm</category><category>privilege-escalation</category><category>broken-access-control</category><category>cwe-863</category><category>api-authorization</category><category>llm-proxy</category></item><item><title>LiteLLM /config/update Broken Access Control (CVE-2026-35029)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35029-litellm-config-broken-access-control/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35029-litellm-config-broken-access-control/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-35029. Status: Weaponized. Affects: LiteLLM proxy. Tags: broken-access-control, litellm, ai-gateway, config-update, ssrf, rce, environment-variable-theft, cwe-863.</description><category>web</category><category>High</category><category>broken-access-control</category><category>litellm</category><category>ai-gateway</category><category>config-update</category><category>ssrf</category><category>rce</category><category>environment-variable-theft</category><category>cwe-863</category></item><item><title>Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-25924 / GHSA-grch-p7vf-vc4f. Status: Weaponized. Affects: Kanboard (project management application). Tags: kanboard, rce, webshell, plugin-installation, incorrect-authorization, cwe-863, cwe-94, admin-bypass, backdoor.</description><category>web</category><category>High</category><category>kanboard</category><category>rce</category><category>webshell</category><category>plugin-installation</category><category>incorrect-authorization</category><category>cwe-863</category><category>cwe-94</category><category>admin-bypass</category><category>backdoor</category></item><item><title>Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28699-gitea-oauth2-scope-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28699-gitea-oauth2-scope-bypass/</guid><description>High severity — web · CVE-2026-28699. Status: PoC. Affects: Gitea (code.gitea.io/gitea). Tags: gitea, oauth2, scope-bypass, basic-auth, incorrect-authorization, cwe-863, api.</description><category>web</category><category>High</category><category>gitea</category><category>oauth2</category><category>scope-bypass</category><category>basic-auth</category><category>incorrect-authorization</category><category>cwe-863</category><category>api</category></item></channel></rss>