WhisperX tag archive

#endpoint_vulnerability

This page collects WhisperX intelligence signals tagged #endpoint_vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-07 07:31:42 · GitHub Issues

1. Mass Assignment Vulnerability in Expensetracker Exposes createExpense Endpoint to Data Manipulation

A critical mass assignment vulnerability has been identified in the expensetracker application, specifically within the createExpense endpoint at ExpenseController.java:52. The flaw allows an attacker to inject additional request body fields—such as 'user' or 'id'—that the application does not explicitly expect, effect...