SecBoard

Red Team

CVEs, Exploits, Offensive-Tools & Vulnerability-Writeups für Pentester und Red-Teamer · 409 Artikel

When a Bug Bounty Isn’t Enough

An enterprise with a long-running public bug bounty shipped a major release. Weeks later, a critical SQL injection surfaced in an authenticated reporting path. More than ten thousand PII records and clear-text card data were reachable via crafted queries. The vulnerable code sat behind role checks...

Original lesen