CVE-2022-24124 - Easy SQL Injection in Casdoor’s Query API – How It Works, Example Exploit, and How to Fix
Casdoor is a well-known open-source authentication platform used by thousands of organizations around the world. But in early 2022, a major security flaw
CVE-2022-23863 - How an Authenticated User Can Change Any Password in Zoho ManageEngine Desktop Central (before 10.1.2137.10)
In February 2022, a critical vulnerability (CVE-2022-23863) was discovered in Zoho’s ManageEngine Desktop Central, affecting software versions prior to 10.1.2137.
CVE-2022-23023 - Understanding the iControl REST Memory Resource Vulnerability in F5 BIG-IP and BIG-IQ
In early 2022, F5 Networks disclosed a new security issue, labeled CVE-2022-23023, affecting several versions of their BIG-IP and BIG-IQ platforms.
CVE-2022-23026 - How Authenticated Low-Privilege Users Can Fill Up Disk Space on BIG-IP ASM & WAF
In January 2022, security researchers discovered CVE-2022-23026, a vulnerability affecting F5 BIG-IP Advanced Web Application Firewall (WAF) and Application Security Manager (ASM)
CVE-2022-23031 - XXE in F5 BIG-IP Advanced WAF & ASM – What You Need to Know
If you’re managing F5 BIG-IP systems, you already know how important security can be. In 2022, a critical vulnerability, CVE-2022-23031, was
Episode
00:00:00
00:00:00