locomotive-cms

1 article
sort: new top best
clear filter
0 5/10

A reflected XSS vulnerability was discovered in Bugcrowd's main domain via an undisclosed 'locale' parameter that was vulnerable to injection attacks. The vulnerability was traced to Locomotive CMS used by multiple websites, allowing attackers to steal user data and perform CSRF attacks; Bugcrowd patched the issue and awarded $600.

Bugcrowd Locomotive CMS WitCoat Security v0sx9b
blog.witcoat.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details