TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.
#CAREER

Find jobs and talents in InfoSec and Cybersecurity.

In our digital climate cyber security is more important than ever, and the need for skilled professionals continues to increase. With the industry offering high-paying and secure jobs, there’s no better time to invest in yourself. If you have a passion for information technology and security, browse our selection of cyber security courses to start the journey to your new career as a cyber security professional.

Find your cybersecurity degree or certification. This guide is intended to provide actionable resources for everyone looking to learn more about the field. Organizationally, the site is broken into several major sections including.

CyberSecurityJobs.com is the No.1 platform for cyber security talent and employers to connect. Every month, thousands of job seekers benefit from our exclusive job posts and focused job search experience. Our employers gain access to an unrivaled audience of cyber security professionals providing them with high-quality applicants and filling vacancies fast.