Quantcast
Channel: /dev/posts/
Viewing all articles
Browse latest Browse all 104

CSRF to RCE in GeckoDriver

$
0
0

A Cross-Site Request Forgery (CSRF) vulnerability I found in GeckoDriver which could be used to execute arbitrary shell commands. CVE-2020-15660 has been assigned to this vulnerability. This was fixed by GeckoDriver v0.27.0 in 2020-07-27. This is bug #1648964.


Viewing all articles
Browse latest Browse all 104

Trending Articles