Back to directory
WRITEUP #1513

LogicalDOC Vulnerability Disclosure

XXERCECommand injectionPrivilege escalation
by@xbadbiddyx(Brett DeWall)
Program
LogicalDOC
Published
Feb 23, 2023
Added to HackDex
Feb 26, 2023
Read Full Writeuphttps://www.whiteoaksecurity.com/blog/logicaldoc-vulnerability-disclosure/
RELATED WRITEUPS
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Escalating From Reader To Contributor In Azure API Management
Privilege Escalation
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write

Built with ❤️ by Shubham Rawat