Resources(82)

  • Reflected XSS vulnerabilities in Squidex "/squid.svg" endpoint

    Ioannis Christodoulakos

    Reflected XSS vulnerabilities were discovered in Squidex (versions before 7.4.0) in the "/squid.svg" endpoint. Attackers can craft malicious links containing injected JavaScript that executes in victims' browsers when opened, potentially leading to session hijacking and account takeover. The issue was fixed in version...

  • e2openplugin OpenWebif saveConfig remote code execution

    John Torakis

    OpenWebif is a Web application that is used in IP TVs and media boxes to provide an easy-to-use Web Interface. It is written mostly in Python (Backend) and JavaScript (Frontend). It can be found in DreamBox devices. A vulnerability was identified in the saveConfig() function.