jwt-bypass

1 article
sort: new top best
clear filter
0 8/10

A multi-stage RCE vulnerability chain in DeskPro helpdesk software exploits insufficient access control on API endpoints to leak JWT secrets and enable admin authentication, followed by insecure deserialization in template editing to achieve remote code execution. The attack chain was demonstrated against Bitdefender's support portal.

CVE-2020-11465 CVE-2020-11463 CVE-2020-11466 CVE-2020-11464 CVE-2020-11467 DeskPro Bitdefender Redforce Web Security JWT TWIG
blog.redforce.io · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details