Vulnerabilities in Cordaware bestinformed
A write-up of CVE-2025-0422, CVE-2025-0423, CVE-2025-0424, and CVE-2025-0425
The first CVEs of 2025 are live!๐จ
We discovered ~10 vulnerabilities in Cordaware bestinformed, leading to 4 CVEs. They can be chained for an unauthenticated compromise of the server and all connected clients.๐พ CVE-2025-042{2..5}
cyllective.com/blog/posts/c...
#blogpost #cybersecurity #CVE #infosec
18.02.2025 10:02 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 1
OAuth Labs: OAuth 2.0 Vulnerabilites
Introducing our latest project: the OAuth Labs. A hands-on approach to OAuth 2.0 vulnerabilities
๐ New from cyllective: ๐๐๐ฎ๐ญ๐ก ๐๐๐๐ฌ ๐
๐ Master OAuth 2.0 with hands-on Docker-based labs:
- JWT signature flaws
- Open redirect risks
- Claim validation issues
๐ป Devs & pentesters: sharpen your skills!
๐ cyllective.com/blog/posts/o...
#OAuth #Cybersecurity #Training #InfoSec #Security
03.12.2024 14:14 โ ๐ 6 ๐ 2 ๐ฌ 0 ๐ 2