How XBOW Found a Scoold Authentication Bypass
xbow.com | vulnerability | #arbitrary-file-read | #vulnerability-research | #open-source | #authentication-bypass | #scoold | #hocon
Summary
XBOW's autonomous auth bypass in Scoold, the open-source Q&A platform: unauthenticated attackers could read or modify the instance config and, via HOCON quirks, read arbitrary files on the host.
- Published
- Collected
Skip to content