Shynet | VERSION 0.13.1
bishopfox.com | blog | #appsec | #vulnerability-research | #security-audit | #web-security | #vulnerability-disclosure | #shynet | #stored-xss | #password-reset-poisoning
Summary
Bishop Fox's audit of Shynet 0.13.1 found two unauthenticated flaws: stored XSS via analytics location/referrer fields, and password-reset poisoning via a spoofed Host header; fixed in 0.14.0.
- Published
- Collected
Skip to content