Menu

#84 SQLI/stored XSS vulnerabilities

v1.0 (example)
open
nobody
None
5
2024-05-07
2022-12-04
ac
No

To the developers,

In the progress of our security research project, we found SQLI/stored XSS vulnerabilities in version 1.0.0 of the application. SQLI Related files: mainmenu.php. stored XSS related files: chess.php, opponentspassword.php

Please contact us at ca224test@gmail.com, so we can provide reproducing steps of the vulnerabilities.
Thank you.

Discussion

  • ac

    ac - 2024-05-07

    we further found request race vulnerabilities in version 1.0.0 of the application. Please contact us at ca224test@gmail.com, so we can provide reproducing steps of the vulnerabilities.

     
  • spacewave

    spacewave - 2024-05-07
     

    Last edit: spacewave 2024-05-14

Log in to post a comment.

MongoDB Logo MongoDB