Tag
critical
advisory
Daptin SQL Injection Vulnerability via Fuzzy Search
2 rules 4 TTPsDaptin versions up to 0.11.4 are vulnerable to SQL injection, where an authenticated user can inject unvalidated column names into raw SQL via the `processFuzzySearch` function, allowing them to read the entire database.
daptin/daptin
sqli
daptin
github
fuzzy-search
2r
4t
critical
advisory
Daptin Unauthenticated Path Traversal and Zip Slip Vulnerability
1 rule 2 TTPsDaptin versions up to and including v0.11.3 are vulnerable to unauthenticated path traversal and zip slip attacks via the cloudstore.file.upload action, allowing arbitrary file write and potential remote code execution.
Daptin
path-traversal
zip-slip
remote-code-execution
1r
2t