CVE-2023-1093

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Account Takeover and Persistence due to the Oauth Misconfiguration

## Team, May you all be well on your side of the screen. :) *. While Doing some research on thehttps://cal.com/, I was able to find a Pre-Account Takeover vulnerability. ## Proof of concept: *. I have ...

Continue Reading
Cross-Site Scripting (XSS)

github.com/mattermost/mattermost-server is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker is able to send AJAX requests on behalf of the victim through OAuth flow completion endpoints v ...

Continue Reading

CVSS3 - MEDIUM

pixiv: Stealing Users OAuth authorization code via redirect_uri

## Summary: Path traversal in OAuth `redirect_uri` which can lead to users authorization code being leaked to any malicious user. The following authorization code flow request is generated at booth lo ...

Continue Reading
Bad magic: new APT found in the area of Russo-Ukrainian conflict

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2020/09/09131757/abstract_random_red_code-990x400.jpg) Since the start of the Russo-Ukrainian conflict, [Kaspersky researchers]() ...

Continue Reading
CVE-2022-4148

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2022-3894

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
CVE-2023-1421

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a m ...

Continue Reading

Back to Main

Subscribe for the latest news: