data-theft

2 articles
sort: new top best
clear filter
0 5/10

A reflected XSS vulnerability was discovered in Bugcrowd's main domain through a secret 'locale' parameter that controlled error page rendering, with the underlying issue traced to Locomotive CMS framework and affecting multiple websites using that platform. The vulnerability could enable CSRF attacks and data theft from the main domain where user submissions are hosted.

Bugcrowd Locomotive CMS WitCoat Security Blog
blog.witcoat.com · devanshbatham/Awesome-Bugbounty-Writeups · 16 hours ago · details
0 3/10

An unauthenticated SQL injection vulnerability in the Elementor Ally WordPress plugin (400k+ installations) allows attackers to steal sensitive data without requiring authentication.

Elementor Ally WordPress
bleepingcomputer.com · Bill Toulas · 2 days ago · details