Account takeover due to blind MongoDB injection
In Summary : I would like to report a privilege escalation vulnerability in flintcms. It allows to reset a known user password, extract its...
https://updatesinfosec.blogspot.com/2018/08/account-takeover-due-to-blind-mongodb.html
I would like to report a privilege escalation vulnerability in flintcms.
It allows to reset a known user password, extract its password reset token [...]
kindly refer the following link as follow up :
https://ift.tt/2MO3FhG