Security Research
CMS, CRM and Forums
- [CVE-2021-27902, CVE-2021-27903]: CraftCMS Zero-day Chain: XSS to SSTI triggering RCE References:
- https://nvd.nist.gov/vuln/detail/CVE-2021-27902
- https://nvd.nist.gov/vuln/detail/CVE-2021-27903
- https://eval.blog/research/craftcms-zero-day-ssti-xss-triggering-rce
- https://github.com/craftcms/cms/commit/8ee85a8f03c143fa2420e7d6f311d95cae3b19ce
- https://github.com/craftcms/cms/commit/c17728fa0bec11d3b82c34defe0930ed409aec38
- Relative Path Traversal in Flarum using fake OAuth Provider References:
- XSS in Unified Transform (A school management software)
- Stored Cross Site Scripting in October CMS
- Cross Site Scripting in digidocu References:
- Internal IP Address leak in Misconfigured WordPress to bypass WAF
Compilers, Interpreters and Languages
- Breaking The Mutant Language's "Encryption (Writeup)"
- CVE-2021-21705: FILTER_VALIDATE_URL bypass in PHP 8
Desktop Applications
Frameworks
PHP Libraries
- CVE-2021-3603: Untrusted code execution in PHPMailer