1.
bishopfox.com | vulnerability | | original ↗ | #xss | #vulnerability-disclosure | #open-redirect | #cms-security
Bishop Fox identified two flaws in Packet Tide's ExpressionEngine 7.3.15, fixed in 7.4.11: unauthenticated XSS (CVE-2024-38454) and open HTTP redirection, which can yield Super Admin accounts.
Skip to content