Sploitus CVE-2025 and CVE-2022 Exploits Targeting Haraj Script
Article Content
- •CVE-2025 involves a POST request exploit affecting Haraj Script users.
- •CVE-2022 is an authenticated stored XSS vulnerability in Haraj Script 3.7.
- •Immediate action is recommended to address both vulnerabilities.
Recent reports detail two vulnerabilities, CVE-2025 and CVE-2022, affecting the Haraj Script. CVE-2025 involves a POST request exploit that could allow unauthorized transactions, impacting users of the Haraj platform. CVE-2022 is an authenticated stored XSS vulnerability in Haraj Script 3.7, potentially affecting users who authenticate on the platform. The exploit for CVE-2025 was disclosed on September 24, 2026, while CVE-2022 was reported on September 28, 2026. The scope of the impact for CVE-2025 is unclear, but it raises concerns about transaction security. The details of CVE-2022 indicate that it could allow attackers to execute scripts in the context of authenticated users. Both vulnerabilities require immediate attention from security professionals to mitigate risks. Currently, there are no confirmed reports of active exploitation for either CVE.
Ask AI about this cluster
Answers cite the sources they use
More articles in this cluster (2)
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…