The second round of the new crypto meetup in munich was held yesterday at the office of FTAPI GmbH. The event was the first of hopefully many more to come and a great opportunity to discuss crypto in browsers and other security topics. FTAPI was not only host, but also initiator and organizer of thi...
Overview A stored XSS vulnerabily was discovered in the ShoutBox module of the enterprise application "BlueSpice Wiki". Title BlueSpice Shoutbox – Stored Cross-Site Scripting Product BlueSpice for MediaWiki Plugin: ShoutBox Vulnerable version 2.23.1 Fixed version 2.23.1.1 Vendor...
Client side access control is at hand, when the process or mechanism that enforces a users set permission is implemented on the users end of the application. The issue with this approach is, that a user has full control over their machine, and therefore the upper hand when it comes to protective mec...