Advisory #57
TitleXSS Hunter Express authentication bypass
CVE IDCVE-2021-41317
Vendor@IAmMandatory
Affected productXSS Hunter Express
Affected versions<= 2021-09-16
Vulnerability typeCWE-287: Improper Authentication
DescriptionXSS Hunter Express has a vulnerability that allows an attacker to bypass the authentication with a crafted request.
StatusFixed in 2021-09-17
RecommendationUpdate to latest commit of the main branch.