scss

1 article
sort: new top best
clear filter
0 7/10
vulnerability

A Local File Inclusion (LFI) vulnerability was discovered in Apigee portals where the SCSS @import directive could be abused to read arbitrary files on the server by referencing paths like /etc/shadow, with compilation errors exposing file contents. The vulnerability was patched by Google shortly after disclosure through their VRP.

Apigee Google Google VRP Drupal 7 healthapix.apigee.io sass-lang.com
offensi.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details