's Avatar

@lpi1

19
Followers
213
Following
3
Posts
12.11.2024
Joined
Posts Following

Latest posts by @lpi1

I hope it's gonna be a fortinet zeroday, I'd like to se De Niro do /../ and then bypass the fix with /..;/

24.12.2024 07:26 👍 1 🔁 0 💬 0 📌 0

The question I often face handling that kind of bugs is weather having to target a specific user (admin) with social engineering would make the attack complexity High or is User interaction "required" enough here to have a realistic CVSS score.

15.11.2024 10:00 👍 0 🔁 0 💬 1 📌 0

In my opinion PR is None as it is a relfected XSS, the attacker does not need privileges to craft the payload and send it to an admin.

15.11.2024 09:56 👍 0 🔁 0 💬 1 📌 0