This writeup details multiple vulnerabilities in Jobberbase 2.0, including local path disclosure, open redirect, XSS (reflected and persistent), unrestricted file upload, code execution via race condition, and SQL injection. It provides technical descriptions and examples for each vulnerability.
Classification
Writeup 90%
Attack Type
Info Leak | Xss | Sqli | Auth Bypass | Other
Target:
Jobberbase 2.0
No auth needed
Prerequisites:
Access to the target application · Ability to send crafted HTTP requests