Is Assessing Your SaaS Providers Worth It? Uncovering an OS Command Injection in a Popular SaaS Platform
projectblack.io | research | #web-security | #vulnerability | #penetration-testing | #education | #saas | #os-command-injection
Summary
A black-box test of a niche SaaS platform used in Australian schools found OS command injection in the login page's username field, confirmed via a 30-second ping delay — underscoring vendor risk.
- Published
- Collected
Skip to content