MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sysappscontrollersapiGf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($p ...
Continue ReadingAugust 08, 2025
Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST reque ...
Continue ReadingAugust 08, 2025
creation_timestamp| type| source ---|---|--- 2025-08-07 23:37:39+00:00| seen|...Read More ...
Continue ReadingAugust 08, 2025
creation_timestamp| type| source ---|---|--- 2025-08-07 23:42:08+00:00| seen|...Read More ...
Continue ReadingAugust 08, 2025
creation_timestamp| type| source ---|---|--- 2025-08-07 21:02:27+00:00| seen|...Read More ...
Continue ReadingAugust 07, 2025
creation_timestamp| type| source ---|---|--- 2025-08-07 21:02:24+00:00| seen|...Read More ...
Continue ReadingAugust 07, 2025
creation_timestamp| type| source ---|---|--- 2025-08-07 21:02:24+00:00| seen|...Read More ...
Continue ReadingAugust 07, 2025
creation_timestamp| type| source ---|---|--- 2025-08-07 21:50:15+00:00| seen|...Read More ...
Continue ReadingAugust 07, 2025
Back to Main