
Episode 11: CV$$, Web Cache Deception, and SSTI
Critical Thinking - Bug Bounty Podcast
00:00
Why LFI's Should Be High?
PayPal was actually paid as a crit too, which is super wild. So here's the CVSS calculation. Attack vector network, attack complexity low, privileges required low. Why do people think LFDs should be a high? I feel like that is, yeah, dude. It's one of those cases where maybe you get locked into CVS or something.
Transcript
Play full episode