home.social

#usdherolab — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #usdherolab, aggregated by home.social.

fetched live
  1. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  2. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  3. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  4. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  5. The pentest professionals at #usdHeroLab identified a vulnerability in #EntraID during a cloud #pentest that allows the circumvention of conditional access policies for privileged identities.

    Two additional vulnerabilities were identified during a web application pentest of #Tenable Nessus Manager, which allow low-privileged users to read arbitrary files at the operating system level.

    All #vulnerabilities were reported to the vendors as part of our Responsible Disclosure policy.

    🔎 You can find detailed information on the #SecurityAdvisories here: usd.de/en/security-advisories-

    #SecurityResearch #SecurityAdvisory #moresecurity #NessusManager #Pentesting #Hacking #CVE_2026_3493 #AppSec #InfoSec #CyberSecurity

  6. Our pentest professionals at #usdHeroLab identified several vulnerabilities in #KofaxCommunicationServer (KCS) and in the #ArcGIS scripting language Arcade ranging from path traversal to XSS.

    All #vulnerabilities were responsibly reported to the vendors.

    👉 Details on our #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Kofax #InfoSec #CyberSecurity #Pentesting #AppSec #Hacking

  7. Our pentest professionals at #usdHeroLab identified several vulnerabilities in #KofaxCommunicationServer (KCS) and in the #ArcGIS scripting language Arcade ranging from path traversal to XSS.

    All #vulnerabilities were responsibly reported to the vendors.

    👉 Details on our #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Kofax #InfoSec #CyberSecurity #Pentesting #AppSec #Hacking

  8. Our pentest professionals at #usdHeroLab identified several vulnerabilities in #KofaxCommunicationServer (KCS) and in the #ArcGIS scripting language Arcade ranging from path traversal to XSS.

    All #vulnerabilities were responsibly reported to the vendors.

    👉 Details on our #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Kofax #InfoSec #CyberSecurity #Pentesting #AppSec #Hacking

  9. Our pentest professionals at #usdHeroLab identified several vulnerabilities in #KofaxCommunicationServer (KCS) and in the #ArcGIS scripting language Arcade ranging from path traversal to XSS.

    All #vulnerabilities were responsibly reported to the vendors.

    👉 Details on our #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Kofax #InfoSec #CyberSecurity #Pentesting #AppSec #Hacking

  10. Our pentest professionals at #usdHeroLab identified several vulnerabilities in #KofaxCommunicationServer (KCS) and in the #ArcGIS scripting language Arcade ranging from path traversal to XSS.

    All #vulnerabilities were responsibly reported to the vendors.

    👉 Details on our #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Kofax #InfoSec #CyberSecurity #Pentesting #AppSec #Hacking

  11. Unauthenticated RCE in Agorum Core Open!

    During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.

    They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.

    📰👉 Detailed information on the published #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec

  12. Unauthenticated RCE in Agorum Core Open!

    During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.

    They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.

    📰👉 Detailed information on the published #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec

  13. Unauthenticated RCE in Agorum Core Open!

    During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.

    They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.

    📰👉 Detailed information on the published #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec

  14. Unauthenticated RCE in Agorum Core Open!

    During their regular security analyses, our pentest professionals from #usdHeroLab examined the open source software #AgorumCoreOpen.

    They discovered multiple #vulnerabilities that, when chained together, allow an unauthenticated attacker to achieve full remote code execution with root privileges. This critical flaw enables complete system compromise without prior authentication.

    📰👉 Detailed information on the published #SecurityAdvisories can be found here: usd.de/en/security-advisories-

    #Pentest #Pentesting #moresecurity #RCE #CyberSecurity #InfoSec

  15. Our #usdHeroLab security analysts have identified a critical #vulnerability in admin panel of #AXIS P1364 Webcam that enables an attacker to create new accounts with administrative privileges.
    Vulnerability type: Cross-Site Request Forgery (CSRF) (CWE-352)
    👇More details: herolab.usd.de/en/security-adv

  16. Our #usdHeroLab security analysts have identified a critical #vulnerability in admin panel of #AXIS P1364 Webcam that enables an attacker to create new accounts with administrative privileges.
    Vulnerability type: Cross-Site Request Forgery (CSRF) (CWE-352)
    👇More details: herolab.usd.de/en/security-adv

  17. Our #usdHeroLab security analysts have identified a critical #vulnerability in admin panel of #AXIS P1364 Webcam that enables an attacker to create new accounts with administrative privileges.
    Vulnerability type: Cross-Site Request Forgery (CSRF) (CWE-352)
    👇More details: herolab.usd.de/en/security-adv

  18. The #usdHeroLab analysts examined the open source application #WeKan while conducting their security analyses and found a #BrokenAccessControl vulnerability.
    🚨Security Risk: High
    🧵👇More details
    herolab.usd.de/en/security-adv

  19. The #usdHeroLab analysts examined the open source application #WeKan while conducting their security analyses and found a #BrokenAccessControl vulnerability.
    🚨Security Risk: High
    🧵👇More details
    herolab.usd.de/en/security-adv

  20. The #usdHeroLab analysts examined the open source application #WeKan while conducting their security analyses and found a #BrokenAccessControl vulnerability.
    🚨Security Risk: High
    🧵👇More details
    herolab.usd.de/en/security-adv

  21. Version 1.3.1 of the #CSTC was released on May 22! It contains lots of new features, improvements and contributions from the community. The CSTC will also be part of the BlackHat USA 2024 Arsenal Labs, looking forward to seeing you! #BHUSA #usdHeroLab #moresecurity github.com/usdAG/cstc

  22. Version 1.3.1 of the #CSTC was released on May 22! It contains lots of new features, improvements and contributions from the community. The CSTC will also be part of the BlackHat USA 2024 Arsenal Labs, looking forward to seeing you! #BHUSA #usdHeroLab #moresecurity github.com/usdAG/cstc

  23. Version 1.3.1 of the #CSTC was released on May 22! It contains lots of new features, improvements and contributions from the community. The CSTC will also be part of the BlackHat USA 2024 Arsenal Labs, looking forward to seeing you! #BHUSA #usdHeroLab #moresecurity github.com/usdAG/cstc

  24. Our #usdHeroLab professionals have uncovered a vulnerability in the online store software #Gambio during their #pentests.

    Our analysts discovered a vulnerability in the password reset functionality. Exploiting this vulnerability would enable an attacker to change the password for any account and take over, for example, the administrator account of the application.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉 More details: herolab.usd.de/en/security-adv

  25. Our #usdHeroLab professionals have uncovered a vulnerability in the online store software #Gambio during their #pentests.

    Our analysts discovered a vulnerability in the password reset functionality. Exploiting this vulnerability would enable an attacker to change the password for any account and take over, for example, the administrator account of the application.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉 More details: herolab.usd.de/en/security-adv

  26. Our #usdHeroLab professionals have uncovered a vulnerability in the online store software #Gambio during their #pentests.

    Our analysts discovered a vulnerability in the password reset functionality. Exploiting this vulnerability would enable an attacker to change the password for any account and take over, for example, the administrator account of the application.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉 More details: herolab.usd.de/en/security-adv

  27. Our #usdHeroLab analysts examined the #SONIX Technology Webcam during their #pentests.

    1️⃣ Vulnerability Type: Incorrect Permission Assignment for Critical Resource (CWE-732)

    🚨 Security Risk: High

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉More Details: herolab.usd.de/security-adviso

  28. Our #usdHeroLab analysts examined the #SONIX Technology Webcam during their #pentests.

    1️⃣ Vulnerability Type: Incorrect Permission Assignment for Critical Resource (CWE-732)

    🚨 Security Risk: High

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉More Details: herolab.usd.de/security-adviso

  29. Our #usdHeroLab analysts examined the #SONIX Technology Webcam during their #pentests.

    1️⃣ Vulnerability Type: Incorrect Permission Assignment for Critical Resource (CWE-732)

    🚨 Security Risk: High

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉More Details: herolab.usd.de/security-adviso

  30. Our #usdHeroLab analysts examined the #SONIX Technology Webcam during their #pentests.

    1️⃣ Vulnerability Type: Incorrect Permission Assignment for Critical Resource (CWE-732)

    🚨 Security Risk: High

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

    👉More Details: herolab.usd.de/security-adviso

  31. #Announcement: On Friday, our #usdHeroLab colleagues published a major release of our BurpSuite Plugin #FlowMate: github.com/usdAG/FlowMate/rele

    During BlackHat USA 2023 and DEF CON 31, our colleagues received a lot of helpful feedback on their #tool: The new version 1.1 contains bug fixes and some new features. In our video, Florian Haag explains the advantages and possible use cases in the context of #WebApplication #Pentests: youtube.com/watch?v=BJhRhGmDAT

    #CheckItOut #Security #Pentesting #Hacking #Tools #Community #moresecurity

  32. #Announcement: On Friday, our #usdHeroLab colleagues published a major release of our BurpSuite Plugin #FlowMate: github.com/usdAG/FlowMate/rele

    During BlackHat USA 2023 and DEF CON 31, our colleagues received a lot of helpful feedback on their #tool: The new version 1.1 contains bug fixes and some new features. In our video, Florian Haag explains the advantages and possible use cases in the context of #WebApplication #Pentests: youtube.com/watch?v=BJhRhGmDAT

    #CheckItOut #Security #Pentesting #Hacking #Tools #Community #moresecurity

  33. #Announcement: On Friday, our #usdHeroLab colleagues published a major release of our BurpSuite Plugin #FlowMate: github.com/usdAG/FlowMate/rele

    During BlackHat USA 2023 and DEF CON 31, our colleagues received a lot of helpful feedback on their #tool: The new version 1.1 contains bug fixes and some new features. In our video, Florian Haag explains the advantages and possible use cases in the context of #WebApplication #Pentests: youtube.com/watch?v=BJhRhGmDAT

    #CheckItOut #Security #Pentesting #Hacking #Tools #Community #moresecurity

  34. Many cooks spoil the tool? Not in the #usdHeroLab: Our colleagues are constantly developing their own #tools, which are subject to strict quality and optimization processes. In the latest video, Florian Haag introduces you to our BurpSuite plugin Cyber Security Transformation Chef (CSTC) and explains how you can use it.

    youtu.be/6fjW4iXj5cg?si=fJCfJU

  35. Many cooks spoil the tool? Not in the #usdHeroLab: Our colleagues are constantly developing their own #tools, which are subject to strict quality and optimization processes. In the latest video, Florian Haag introduces you to our BurpSuite plugin Cyber Security Transformation Chef (CSTC) and explains how you can use it.

    youtu.be/6fjW4iXj5cg?si=fJCfJU

  36. Many cooks spoil the tool? Not in the #usdHeroLab: Our colleagues are constantly developing their own #tools, which are subject to strict quality and optimization processes. In the latest video, Florian Haag introduces you to our BurpSuite plugin Cyber Security Transformation Chef (CSTC) and explains how you can use it.

    youtu.be/6fjW4iXj5cg?si=fJCfJU

  37. Our #usdHeroLab #Pentest professionals analyzed #FileCloud during their pentests.
    1⃣Vulnerability Type: Dependency on Vulnerable Third-Party Component (CWE-1395)
    🚨Security Risk: Critical

    🧐FileCloud is an enterprise solution for accessing, synchronizing and sharing files hosted on your servers.
    The identified vulnerability is related to an outdated Electron dependency. Exploiting this vulnerability could potentially allow attackers to gain unauthorized access to sensitive data stored within the application.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 👩‍💻​👩‍💻​👇
    herolab.usd.de/security-adviso

  38. Our #usdHeroLab #Pentest professionals analyzed #FileCloud during their pentests.
    1⃣Vulnerability Type: Dependency on Vulnerable Third-Party Component (CWE-1395)
    🚨Security Risk: Critical

    🧐FileCloud is an enterprise solution for accessing, synchronizing and sharing files hosted on your servers.
    The identified vulnerability is related to an outdated Electron dependency. Exploiting this vulnerability could potentially allow attackers to gain unauthorized access to sensitive data stored within the application.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 👩‍💻​👩‍💻​👇
    herolab.usd.de/security-adviso

  39. Our #usdHeroLab #Pentest professionals analyzed #FileCloud during their pentests.
    1⃣Vulnerability Type: Dependency on Vulnerable Third-Party Component (CWE-1395)
    🚨Security Risk: Critical

    🧐FileCloud is an enterprise solution for accessing, synchronizing and sharing files hosted on your servers.
    The identified vulnerability is related to an outdated Electron dependency. Exploiting this vulnerability could potentially allow attackers to gain unauthorized access to sensitive data stored within the application.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 👩‍💻​👩‍💻​👇
    herolab.usd.de/security-adviso

  40. Our #usdHeroLab #Pentest professionals analyzed #Gambio during their pentests.
    1⃣Vulnerability Type: several vulnerabilities with partly high risk
    🚨Security Risk: Critical
    🧵👇 More Details

    🧐Gambio is a software designed for running online shops. It provides various features and tools to help businesses manage their inventory, process orders, and handle customer interactions.

    The identified vulnerabilities allowed unauthenticated attackers to execute code on the underlying system, because the application deserializes untrusted data. Other vulnerabilities allowed unauthenticated attackers to perform SQL injection attacks to extract data from the database. Also the application stores the passwords provided during the installation process in cleartext.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 🧑‍💻👩‍💻 👇
    herolab.usd.de/en/security-adv

  41. Our #usdHeroLab #Pentest professionals analyzed #Gambio during their pentests.
    1⃣Vulnerability Type: several vulnerabilities with partly high risk
    🚨Security Risk: Critical
    🧵👇 More Details

    🧐Gambio is a software designed for running online shops. It provides various features and tools to help businesses manage their inventory, process orders, and handle customer interactions.

    The identified vulnerabilities allowed unauthenticated attackers to execute code on the underlying system, because the application deserializes untrusted data. Other vulnerabilities allowed unauthenticated attackers to perform SQL injection attacks to extract data from the database. Also the application stores the passwords provided during the installation process in cleartext.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 🧑‍💻👩‍💻 👇
    herolab.usd.de/en/security-adv

  42. Our #usdHeroLab #Pentest professionals analyzed #Gambio during their pentests.
    1⃣Vulnerability Type: several vulnerabilities with partly high risk
    🚨Security Risk: Critical
    🧵👇 More Details

    🧐Gambio is a software designed for running online shops. It provides various features and tools to help businesses manage their inventory, process orders, and handle customer interactions.

    The identified vulnerabilities allowed unauthenticated attackers to execute code on the underlying system, because the application deserializes untrusted data. Other vulnerabilities allowed unauthenticated attackers to perform SQL injection attacks to extract data from the database. Also the application stores the passwords provided during the installation process in cleartext.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 🧑‍💻👩‍💻 👇
    herolab.usd.de/en/security-adv

  43. Our #usdHeroLab #Pentest professionals analyzed #IBMQRadarSIEM during their pentests.
    1⃣Vulnerability Type: Cross-site Scripting #CWE79
    🚨Security Risk: Medium
    🔎CVE number: CVE-2023-43057
    👇More Details

    🧐IBM QRadar SIEM is a security information and event management platform developed by IBM that provides advanced threat detection for its users. The vulnerability can be used to perform actions on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  44. Our #usdHeroLab #Pentest professionals analyzed #IBMQRadarSIEM during their pentests.
    1⃣Vulnerability Type: Cross-site Scripting #CWE79
    🚨Security Risk: Medium
    🔎CVE number: CVE-2023-43057
    👇More Details

    🧐IBM QRadar SIEM is a security information and event management platform developed by IBM that provides advanced threat detection for its users. The vulnerability can be used to perform actions on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  45. Our #usdHeroLab #Pentest professionals analyzed #IBMQRadarSIEM during their pentests.
    1⃣Vulnerability Type: Cross-site Scripting #CWE79
    🚨Security Risk: Medium
    🔎CVE number: CVE-2023-43057
    👇More Details

    🧐IBM QRadar SIEM is a security information and event management platform developed by IBM that provides advanced threat detection for its users. The vulnerability can be used to perform actions on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  46. Our #usdHeroLab #Pentest professionals analyzed #IBMQRadarSIEM during their pentests.
    1⃣Vulnerability Type: Cross-site Scripting #CWE79
    🚨Security Risk: Medium
    🔎CVE number: CVE-2023-43057
    👇More Details

    🧐IBM QRadar SIEM is a security information and event management platform developed by IBM that provides advanced threat detection for its users. The vulnerability can be used to perform actions on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  47. Ever wondered how attackers can break out of the #Citrix encapsulation and infiltrate the underlying system? It becomes a critical issue when IT environments lack proper virtualization readiness. Addressing these attack vectors requires a special approach. Dive into our latest #LabNews blog post to get insights into what to look out for during your #PentrationTest of virtualized applications 👨‍💻​👩‍💻​👇​
    herolab.usd.de/en/pentest-virt

    #moresecurity #usdHeroLab #CitrixBreakOut #CitrixSecurity

  48. Ever wondered how attackers can break out of the #Citrix encapsulation and infiltrate the underlying system? It becomes a critical issue when IT environments lack proper virtualization readiness. Addressing these attack vectors requires a special approach. Dive into our latest #LabNews blog post to get insights into what to look out for during your #PentrationTest of virtualized applications 👨‍💻​👩‍💻​👇​
    herolab.usd.de/en/pentest-virt

    #moresecurity #usdHeroLab #CitrixBreakOut #CitrixSecurity

  49. Ever wondered how attackers can break out of the #Citrix encapsulation and infiltrate the underlying system? It becomes a critical issue when IT environments lack proper virtualization readiness. Addressing these attack vectors requires a special approach. Dive into our latest #LabNews blog post to get insights into what to look out for during your #PentrationTest of virtualized applications 👨‍💻​👩‍💻​👇​
    herolab.usd.de/en/pentest-virt

    #moresecurity #usdHeroLab #CitrixBreakOut #CitrixSecurity

  50. Ever wondered how attackers can break out of the #Citrix encapsulation and infiltrate the underlying system? It becomes a critical issue when IT environments lack proper virtualization readiness. Addressing these attack vectors requires a special approach. Dive into our latest #LabNews blog post to get insights into what to look out for during your #PentrationTest of virtualized applications 👨‍💻​👩‍💻​👇​
    herolab.usd.de/en/pentest-virt

    #moresecurity #usdHeroLab #CitrixBreakOut #CitrixSecurity

  51. Our #usdHeroLab #Pentest professionals analyzed #GibbonEdu during their pentests.
    1⃣Vulnerability Type: Arbitrary File Write #CWE434
    🚨 Security Risk: Critical
    🔎CVE number: CVE-2023-45878
    🧵👇 More Details

    🧐 Gibbon Edu is an #opensource educational software designed for #schools and #institutions to manage their administrative and academic processes. It offers a range of features to facilitate communication, collaboration, and organization within the educational community.

    The identified vulnerability allowed unauthenticated attackers to upload arbitrary files to the application and receive code execution on the underlying system. To receive #RCE an attacker must craft a fake image which can be stored as PHP file.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 🧑‍💻👩‍💻👇
    herolab.usd.de/security-adviso

  52. Our #usdHeroLab #Pentest professionals analyzed #GibbonEdu during their pentests.
    1⃣Vulnerability Type: Arbitrary File Write #CWE434
    🚨 Security Risk: Critical
    🔎CVE number: CVE-2023-45878
    🧵👇 More Details

    🧐 Gibbon Edu is an #opensource educational software designed for #schools and #institutions to manage their administrative and academic processes. It offers a range of features to facilitate communication, collaboration, and organization within the educational community.

    The identified vulnerability allowed unauthenticated attackers to upload arbitrary files to the application and receive code execution on the underlying system. To receive #RCE an attacker must craft a fake image which can be stored as PHP file.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 🧑‍💻👩‍💻👇
    herolab.usd.de/security-adviso

  53. Our #usdHeroLab #Pentest professionals analyzed #GibbonEdu during their pentests.
    1⃣Vulnerability Type: Arbitrary File Write #CWE434
    🚨 Security Risk: Critical
    🔎CVE number: CVE-2023-45878
    🧵👇 More Details

    🧐 Gibbon Edu is an #opensource educational software designed for #schools and #institutions to manage their administrative and academic processes. It offers a range of features to facilitate communication, collaboration, and organization within the educational community.

    The identified vulnerability allowed unauthenticated attackers to upload arbitrary files to the application and receive code execution on the underlying system. To receive #RCE an attacker must craft a fake image which can be stored as PHP file.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 🧑‍💻👩‍💻👇
    herolab.usd.de/security-adviso

  54. Our #usdHeroLab #Pentest professionals analyzed #GibbonEdu during their pentests.
    1⃣Vulnerability Type: Arbitrary File Write #CWE434
    🚨 Security Risk: Critical
    🔎CVE number: CVE-2023-45878
    🧵👇 More Details

    🧐 Gibbon Edu is an #opensource educational software designed for #schools and #institutions to manage their administrative and academic processes. It offers a range of features to facilitate communication, collaboration, and organization within the educational community.

    The identified vulnerability allowed unauthenticated attackers to upload arbitrary files to the application and receive code execution on the underlying system. To receive #RCE an attacker must craft a fake image which can be stored as PHP file.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 🧑‍💻👩‍💻👇
    herolab.usd.de/security-adviso

  55. The #usdHeroLab analysts examined #ThingsBoard while conducting their #pentests.
    1⃣Vulnerability Type: Server-Side Template Injection
    🚨Security Risk: High
    🧵👇 More Details

    🧐ThingsBoard is an open-source IoT platform for data collection, processing, visualization, and device management.

    During an assessment a Server-Side Template Injection (SSTI) vulnerability has been discovered. It enables attackers to dynamically create and modify templates, that are used for automated generation of mail content, which results in the execution of arbitrary system commands.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  56. The #usdHeroLab analysts examined #ThingsBoard while conducting their #pentests.
    1⃣Vulnerability Type: Server-Side Template Injection
    🚨Security Risk: High
    🧵👇 More Details

    🧐ThingsBoard is an open-source IoT platform for data collection, processing, visualization, and device management.

    During an assessment a Server-Side Template Injection (SSTI) vulnerability has been discovered. It enables attackers to dynamically create and modify templates, that are used for automated generation of mail content, which results in the execution of arbitrary system commands.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  57. The #usdHeroLab analysts examined #ThingsBoard while conducting their #pentests.
    1⃣Vulnerability Type: Server-Side Template Injection
    🚨Security Risk: High
    🧵👇 More Details

    🧐ThingsBoard is an open-source IoT platform for data collection, processing, visualization, and device management.

    During an assessment a Server-Side Template Injection (SSTI) vulnerability has been discovered. It enables attackers to dynamically create and modify templates, that are used for automated generation of mail content, which results in the execution of arbitrary system commands.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy and subsequently fixed for #moresecurity. More information can be found here 👩‍💻​👨‍💻​👇

    herolab.usd.de/en/security-adv

  58. The #usdHeroLab analysts examined the Content Management System #SuperWebMailer while conducting their #pentests.
    1⃣Vulnerability Type: Improper Neutralization of Input During Web Page Generation (CWE-79)
    🚨 Security Risk: Medium
    👇🧵 More Details

    🧐SuperWebMailer is an online application for managing e-mail newsletters. The vulnerability enabled attackers to execute requests on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 👩‍💻🧑‍💻 👇

    herolab.usd.de/security-adviso

  59. The #usdHeroLab analysts examined the Content Management System #SuperWebMailer while conducting their #pentests.
    1⃣Vulnerability Type: Improper Neutralization of Input During Web Page Generation (CWE-79)
    🚨 Security Risk: Medium
    👇🧵 More Details

    🧐SuperWebMailer is an online application for managing e-mail newsletters. The vulnerability enabled attackers to execute requests on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 👩‍💻🧑‍💻 👇

    herolab.usd.de/security-adviso

  60. The #usdHeroLab analysts examined the Content Management System #SuperWebMailer while conducting their #pentests.
    1⃣Vulnerability Type: Improper Neutralization of Input During Web Page Generation (CWE-79)
    🚨 Security Risk: Medium
    👇🧵 More Details

    🧐SuperWebMailer is an online application for managing e-mail newsletters. The vulnerability enabled attackers to execute requests on behalf of other users.

    The vulnerability was reported to the vendor under the Responsible Disclosure Policy. More information can be found here 👩‍💻🧑‍💻 👇

    herolab.usd.de/security-adviso