fix-format

patch-1
Dhiyaneshwaran 2024-04-12 15:45:38 +05:30 committed by GitHub
parent f583cef033
commit 63e52d64a2
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 2 additions and 2 deletions

View File

@ -4,10 +4,10 @@ info:
name: ReCrystallize Server - Authentication Bypass
author: Carson Chan
severity: high
reference:
- https://preview.sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/
description: |
This vulnerability allows an attacker to bypass authentication in the ReCrystallize Server application by manipulating the 'AdminUsername' cookie. This gives the attacker administrative access to the application's functionality, even when the default password has been changed.
reference:
- https://preview.sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/
metadata:
verified: true
max-request: 1