Vendor
high
advisory
OAuth Redirect URI Validation Bypass in Ech0
1 TTP 2 CVEsEch0 versions 4.5.6 and earlier contain an OAuth redirect URI validation flaw that permits attackers to intercept authorization codes, enabling full account compromise.
PoC
Ech0 +1
1t
2c
high
advisory
Ech0 Scoped Admin Access Token Bypass
2 rules 1 TTPEch0 scoped access tokens do not reliably enforce least privilege, leading to privilege escalation and data exfiltration by allowing low-scope admin tokens to access broader admin functionality, including backup exports.
Ech0
privilege-escalation
data-exfiltration
access-token
2r
1t