ended4월 20일· 1 sources
Pretalx Bug Enables Weaponized Phishing via Trusted System Emails
Pretalx 보안 결함 발견, 공식 메일을 피싱 무기로 악용 가능
Why it matters
This vulnerability is critical because it allows attackers to bypass standard security protocols like SPF and DMARC by using the official server to send malicious content. Since the emails originate from a legitimate source, users are far more likely to trust the embedded links, making it a potent tool for targeted phishing.
1
Sources
+0
24h
—
Growth
152d
Active
PretalxEmail InjectionTemplate InjectionCWE-1336Phishing Attack