enumeration

2 articles
sort: new top best
clear filter
0 7/10

A researcher discovered a critical vulnerability chain in a multi-tenant business data management app: predictable, non-expiring invitation tokens with no signature protection allowed brute-forcing access to organizations, coupled with a secondary issue allowing visibility of pending admin invitations enabled full organizational takeover with minimal detection risk.

Plenum InfoSec Write-ups
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details
0 7/10

A Time-Based SQL Injection vulnerability discovered in a forget password function of an ASP.NET application, exploited through single-quote escaping to break the SQL query and WAITFOR DELAY statements to exfiltrate database information using SQLMap automation.

SQLMap Burp Suite MSSQL ASP.NET
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details