CVE-2025-62523Medium· 6.3▾ SunlitPILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in the Access-Control-Allow-Origin response header without proper validation or a whitelist, while Access-Control-Allow-Credentials is set to true. This behavior could allow a malicious website on a different origin to send requests (including credentials) to the PILOS API. This may enable exfiltration or actions using the victim’s credentials if the server accepts those cross-origin requests as authenticated. Laravel’s session handling applies additional origin checks such that cross-origin requests are not authenticated by default. Because of these session-origin protections, and in the absence of any other unknown vulnerabilities that would bypass Laravel’s origin/session checks, this reflected-Origin CORS misconfiguration is not believed to be exploitable in typical PILOS deployments. This vulnerability has been patched in PILOS in v4.8.0
pilos < 4.8.0Upgrade past the affected range:
pilos 4.8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62524Medium· 5.3PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton
CVE-2025-62781Medium· 5.0PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton
GHSA-v2f8-6655-7grjCritical· 10.0Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
CVE-2024-23578Medium· 4.2HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).
CVE-2026-66247Medium· 4.3iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrat…
CVE-2026-66070High· 7.6RabbitMQ is a messaging and streaming broker