
evilqr
Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.
authenticationpenetration-testingphishing+4
4093 years ago

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.


【Teedy 1.11】Account Takeover via XSS

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

PoC for CVE-2022-48429 - Youtrack stored XSS

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…