CVE-2020-13654 - My First CVE: XSS > CSRF > Privesc to ADMIN

Finding your first CVE is one of those things that stays with you. Not so much for the assigned number, which is ultimately just an identifier in a database, but for the process: the moment you realize the bug is real, that nobody has reported it before you, and that you have the responsibility to handle it correctly. I’m telling this story in this post from start to finish: the discovery, the exploit, and finally the responsible disclosure process with MITRE. ...

Pubblicato il 30/12/2020 · 10 min · 2110 words · Astaruf