Outpost24 logo
CVE-2024-58248: Race condition vulnerability leaves nopCommerce at risk of...
Application Security
I recently discovered an interesting race condition vulnerability in the eCommerce software nopCommerce, during a manual pen test as part...
Graphic for blog on OAuth vulnerabilities
Tokens & traps: Seven common OAuth vulnerabilities (plus mitigations)
Application Security
In the world of modern web applications, the OAuth flow is our trusty gatekeeper, enabling seamless logins and secure data...
Thumbnail for CyberFlex (EASM + PTaaS)
How external attack surface analysis enhances pen testing 
Application Security
Despite advancements in security, web applications are still a problem. Attackers target web applications because they’re exposed, complex, and not...
Blue open lock as symbol for authentification
6 common authentication vulnerabilities in web apps  
Application Security
Authentication is used by most web applications. Both for letting users have access to individual accounts, but also for protecting...
Outpost24 logo
CrushFTP auth bypass vulnerability: Disclosure mess leads to attacks 
Application Security
Outpost24 analysts recently discovered a critical authentication bypass vulnerability in CrushFTP, identified as CVE-2025-31161. The vulnerability has a CVSSv3.1 score...