Posts

Showing posts from March, 2026

URL Redirect Bypass via Weak String Validation Leading to Attacker-Controlled Domain Redirection

Breaking Directus CMS < 11.9.3 ( From Information Disclosure to Arbitrary File Overwrite )

How I Exploited a CORS Misconfiguration To a Full Account Takeover Chain