Posted by Juraj Kosik on May 17
VULNERABILITYNon-sanitised submission of malicious SVG files on the Edupage portal in
combination with CSRF vulnerability allows triggering various actions on
behalf of other users, e.g. identity spoofing, sending fake messages,
giving fake approvals, etc.
Full disclosure report:
VENDOR:
Applied Software Consultants
PRODUCT:
Edupage - https://www.edupage.org/
Web...
SOCIAL SHARE CARD GENERATOR