Stealing OAuth tokens of connected Microsoft accounts via open redirect in Harvest App October 21, 2023 ◦ 4 min ◦ Security
CraftCMS Zero-day Chain: XSS to SSTI triggering RCE Public Disclosure of CVE-2021-27902 and CVE-2021-27903 July 29, 2021 ◦ 14 min ◦ Security
Code Execution via Cross Site Scripting in Tagspaces (A file manager) June 11, 2021 ◦ 1 min ◦ Security
Internal IP Address leak in Misconfigured WordPress to bypass WAF December 27, 2020 ◦ 3 min ◦ Security
Account Takeover on unverified emails in File Sync & Share in Acronis June 24, 2020 ◦ 1 min ◦ Security