Sploitus Multiple CVEs Expose Vulnerabilities in PHP and Collabora CODE
Article Content
- •CVE-2015-57115 affects PHP applications and allows path traversal exploitation.
- •CVE-2020-12432 in Collabora CODE can lead to stored XSS attacks and data theft.
- •Both vulnerabilities require immediate attention from security professionals.
Two critical vulnerabilities have been reported: CVE-2015-57115, a path traversal vulnerability in PHP applications, and CVE-2020-12432, a stored XSS vulnerability in Collabora CODE versions up to 4.2.2. The CVE-2015-57115 exploit allows attackers to check multiple URLs for vulnerabilities using a Python script, while CVE-2020-12432 enables attackers to exploit the WOPI API to steal user data via XSS. The latter requires a specially crafted HTML document to execute the attack. Both vulnerabilities pose significant risks to affected systems, with the potential for data breaches and unauthorized access. Current status indicates that both vulnerabilities are known, with CVE-2015-57115 having a public proof-of-concept available. Security professionals are advised to assess their systems for these vulnerabilities and apply necessary mitigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2015-57115 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…