Sharepoint Dynamic Proxy Generator Remote Command Execution Exploit

This Metasploit module exploits two vulnerabilities in Sharepoint 2019 - an authentication bypass as noted in CVE-2023-29357 which was patched in June of 2023 and CVE-2023-24955 which was a remote com ...

Continue Reading
Session Token in URL in directus

Impact When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g., web server logs, brow ...

Continue Reading
GHSA-C8V6-786G-VJX6 vulnerabilities

Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...

Continue Reading
GHSA-C8V6-786G-VJX6 vulnerabilities

Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...

Continue Reading
Session Token in URL in directus

Impact When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g., web server logs, brow ...

Continue Reading
CVE-2023-51774 vulnerabilities

Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...

Continue Reading
Cross site request forgery (csrf)

Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security ri ...

Continue Reading
CVE-2023-51774 vulnerabilities

Vulnerabilities for packages: ruby3.2-json-jwt,...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: