XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/mandatoryprogrammer/xsshunter-express/commit/56bb44ed9024849f64173f71583ecb7d873baba0 | third party advisory patch |
https://docs.google.com/document/d/12rq4YIFZLSmZlEsq7d7hYCI1qO5xyIxA1Wrs1m4y9-4/preview | third party advisory mitigation |
https://vuln.ryotak.me/advisories/57 | third party advisory |