THE KNOWLEDGE IS THE WORK.
Resources(82)
Weak SVG asset filtering mechanism in Squidex
Charalampos Maraziaris
CENSUS has discovered a stored cross site scripting (XSS) vulnerability in the Squidex "headless" open source CMS framework. The vulnerability affects all versions of Squidex prior to 7.9.0 and enables privilege escalation affecting authenticated victim users. The Squidex development team has addressed the issue in...
Reflected XSS vulnerabilities in Squidex "/squid.svg" endpoint
Ioannis Christodoulakos
Reflected XSS vulnerabilities were discovered in Squidex (versions before 7.4.0) in the "/squid.svg" endpoint. Attackers can craft malicious links containing injected JavaScript that executes in victims' browsers when opened, potentially leading to session hijacking and account takeover. The issue was fixed in version...