Elektrine lite

← Feed

@cR0w@infosec.exchange

2026-10-05 13:34 UTC

Yet another perfect 10 this morning. This one from a company that knows its way around perfect 10s. 🥳 https://www.cve.org/CVERecord?id=CVE-2026-92931 sev:CRIT 10.0 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

Replies (0)

No replies.