Home
Rohan Pagey
Cancel

Cve 2022–33077 Idor To Change Address Of Any Customer Via Parameter Pollution In Nopcommerce

Description There is an access control vulnerability affecting nopCommerce (≤ 4.50.2) and also affecting the upcoming beta version (4.60). The vulnerability lies in the “addressedit” endpoint, and...

Cve 2019 25060 Improper Access Control In Wpgraphql Leaks Wordpress Account Roles

Description The WPGraphQL plugin (v < 0.3.5) doesn’t properly restrict access to information about other users’ roles on the affected wordpress site. Because of this, a remote attacker could fo...

Edmodo Idor To View Private Files Of Any Class

What is Edmodo ? It’s a platform to connect teachers-students-parents. Kind of social networking for learning. Functionality Edmodo is having a functionality called classes. A teacher can c...