Skip to content

Instantly share code, notes, and snippets.

View alm4ric's full-sized avatar
💭
"><svg/onload=prompt()>

alm4ric

💭
"><svg/onload=prompt()>
View GitHub Profile
[Suggested description]
The Untangle NG firewall 14.2.0 is vulnerable to authenticated
inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
[Additional Information]
I can share the report - containing the technical details and proof of the vulnerability - which I reported to Untangle. If needed, please let me know via PGP e-mail.
[Vulnerability Type]