WhisperX tag archive

#admin-privilege

This page collects WhisperX intelligence signals tagged #admin-privilege. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-01 23:27:07 · GitHub Issues

1. ViUR Admin Session Hijack: Open Redirect in `get_cookie_for_app` Exposed Privileged Credentials

A critical open-redirect vulnerability in the ViUR framework's `get_cookie_for_app` endpoint allowed attackers to steal admin session cookies with a single malicious link. The flaw was in the endpoint's handling of the `redirect_to` parameter, which appended the user's session cookie as a plain query parameter to any s...