Vendor
high
advisory
Daptin SQL Injection Vulnerability in Aggregate API
2 rules 1 TTPA SQL injection vulnerability exists in Daptin versions prior to 0.11.4 within the `/aggregate/:typename` endpoint, where the `column` and `group` query parameters are passed to `goqu.L()` without validation, allowing authenticated users to inject arbitrary SQL expressions and exfiltrate sensitive data.
Daptin
sql-injection
web-application
2r
1t
critical
advisory
Daptin Unauthenticated Path Traversal and Zip Slip Vulnerability
1 rule 2 TTPsDaptin versions up to and including v0.11.3 are vulnerable to unauthenticated path traversal and zip slip attacks via the cloudstore.file.upload action, allowing arbitrary file write and potential remote code execution.
Daptin
path-traversal
zip-slip
remote-code-execution
1r
2t