Product
high
advisory
Authentication Bypass in Dinky SysConfigController
1 rule 2 TTPs 1 CVEDinky v1.2.5 and development builds contain an authentication bypass in the SysConfigController.getAll handler, allowing unauthenticated remote attackers to retrieve cleartext system credentials and service tokens.
Dinky
1r
2t
1c
critical
advisory
Critical Path Traversal and RCE in Dinky
1 rule 1 TTP 1 CVEDinky v1.2.5 contains a path traversal vulnerability in the /download/uploadFromRsByLocal endpoint, which is protected by a hardcoded authentication token, allowing unauthenticated attackers to achieve arbitrary file write and remote code execution.
Dinky
1r
1t
1c