Enjin: Revocation API Token by Bypassing The XSRF Token

@alpernae was able to demonstrate that the Enjin Platform's GraphQL interface was missing the appropriate CSRF protection when using a session token. The attack is performed by crafting a malicio ...

Continue Reading
Improper Authorization

@evershop/evershop is vulnerable to Improper Authorization. The vulnerability is due to lack of authorization checks while accessing GraphQL endpoints, resulting in Remote attackers extracting sensiti ...

Continue Reading
EverShop vulnerable to improper authorization in GraphQL endpoints

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL...Read More ...

Continue Reading
CVE-2022-1563

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
HackerOne: View Titles of Private Reports with pending email invitation

Summary: If a private report has a pending email invitation for collaboration, an anonymous user can see the title of the report. This only works for anonymous users, and the collaboration invitation ...

Continue Reading
HackerOne: View Titles of Private Reports with pending email invitation

Summary: If a private report has a pending email invitation for collaboration, an anonymous user can see the title of the report. This only works for anonymous users, and the collaboration invitation ...

Continue Reading
HackerOne: View Titles of Private Reports with pending email invitation

Summary: If a private report has a pending email invitation for collaboration, an anonymous user can see the title of the report. This only works for anonymous users, and the collaboration invitation ...

Continue Reading
CVE-2023-46942

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: