Today's fun adventure with #peertube involves the #exploit fixed in 8.1.6.
Uncategorized
1
Posts
1
Posters
0
Views
-
Today's fun adventure with #peertube involves the #exploit fixed in 8.1.6. This one has an SQL injection hole. Looks like they got into mine, but apparently nothing was done to it yet. If you're curious, here's what the exploit pushed in the actor table:
So this worked because they had a ' after the URL. #infosec