Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-34413
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Legality WHISTLEBLOWING Missing Critical HTTP Security Headers
Source: NVD (National Vulnerability Database)
Vulnerability Description
Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy (with CSP delivered via HTML meta elements being inadequate). The absence of these headers weakens browser-side defenses and increases exposure to client-side attacks such as cross-site scripting, clickjacking, referer leakage, and cross-origin data disclosure.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
保护机制失效
Source: NVD (National Vulnerability Database)
Vulnerability Title
DigitalPA Legality WHISTLEBLOWING 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DigitalPA Legality WHISTLEBLOWING是意大利DigitalPA公司的一个用于管理举报的软件系统。 DigitalPA Legality WHISTLEBLOWING存在安全漏洞,该漏洞源于缺少关键HTTP安全头,可能导致跨站脚本和点击劫持攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
DigitalPA S.r.l.Legality WHISTLEBLOWING 0 -
II. Public POCs for CVE-2025-34413
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-34413
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-34413

No comments yet


Leave a comment