  1. Seongil Wi

    XSS in installation script

    Hi, Our research team in KAIST WSP Lab found a reflected vulnerability in chevereto-free (https://github.com/Chevereto/Chevereto-Free). I post this thread to report the found bug - Description: An reflected XSS vulnerability was identified in the ready.php page in the installation process due...
  2. I

    Possible XSS Bug

    ▶🚶‍Reproduction steps Select an image for upload, then edit image title-description and write "><svg/onload=prompt(document.domain);> After upload image and visit your uploaded image, you got a message 😢Unexpected result Example image url ; https://imgyukle.com/i/YOPlUj...
  3. Rodolfo

    Chevereto v3.14.0

    Hey there, The next minor release is in the works and this is the changelog (so far): Chevereto v3.14.0 pre-release notes Added support for WebP Added brute force protection for cookie based login attempts Added auth token at /update (CSRF) Added HTTP only and secure cookie flags Added...