← Back to feed
Vulnerabilities & PatchesEmerging1 sourceNov 17, 2022 · 19:48via API Security News

Issue 209: CSRF in Plesk API-enabled server, top five API security myths, Ory Hydra authentication server

Brief

This week, we have new research from FORTBRIDGE that reveals a client-side request forgery (CSRF) vulnerability in API-enabled instances of Plesk, the popular server administration portal. We also have an article on the top five API security myths according to Hacker News, a quick look at the Ory Hydra OAuth2/OIDC server, and a guide to some awesome BurpSuite extensions.

Vulnerability: CSRF in Plesk API-enabled server

First up this week is breaking research from our friends at FORTBRIDGE which uncovered a CSRF vulnerability in the REST API of the popular server administration tool, Plesk. Plesk is widely used as an administrative front-end for web hosting and data center providers, and has generally been hardened and patched against security vulnerabilities.

Read more on API Security News