PWNONE Knowledge Base

Knowledge Base

Explore the latest attack vectors, cybersecurity trends and best practices for building secure software.

All articles (10)

Ping Me and I’ll Tell You Who You Are. A Double IDOR in CVAT Webhooks (CVE-2024-45393)
Zero-Day
12 min read·March 17, 2026

Ping Me and I’ll Tell You Who You Are. A Double IDOR in CVAT Webhooks (CVE-2024-45393)

Predictable identifiers and missing authorization on the webhook endpoints in CVAT enabled data theft and created a DoS risk. A double IDOR with the official identifier CVE-2024-45393.

Marcin MotwickiMarcin Motwicki
Read
When an int Becomes a Malicious Script. Reflected XSS in CVAT (CVE-2024-47064)
Zero-Day
8 min read·March 17, 2026

When an int Becomes a Malicious Script. Reflected XSS in CVAT (CVE-2024-47064)

A lack of input type validation and output encoding allowed injecting malicious JavaScript into the victim’s browser. Reflected XSS in CVAT scored CVSS 8.1 (High).

Marcin MotwickiMarcin Motwicki
Read
Change One HTTP Method and... You Walk Right In. A Classic IDOR in CVAT (CVE-2024-47172)
Zero-Day
10 min read·March 17, 2026

Change One HTTP Method and... You Walk Right In. A Classic IDOR in CVAT (CVE-2024-47172)

Changing the HTTP method from GET to PATCH was enough to bypass access control in the popular CVAT tool. A classic IDOR vulnerability with the official identifier CVE-2024-47172.

Marcin MotwickiMarcin Motwicki
Read
When an Application Says Too Much. Information Exposure in CVAT (No CVE)
Zero-Day
9 min read·March 17, 2026

When an Application Says Too Much. Information Exposure in CVAT (No CVE)

No CVE does not mean no risk. Two vectors for leaking sensitive diagnostic data in CVAT, from system paths to the internal Nuclio microservice architecture. A classic case of CWE-497.

Marcin MotwickiMarcin Motwicki
Read
A Recipe for Disaster. Unauthenticated PHP Object Injection in the Cooked Pro Plugin (CVE-2022-3900)
Zero-Day
10 min read·March 17, 2026

A Recipe for Disaster. Unauthenticated PHP Object Injection in the Cooked Pro Plugin (CVE-2022-3900)

A recipe plugin + the unserialize() function = a recipe for disaster. Unauthenticated PHP Object Injection in Cooked Pro, CVSS 9.8 (Critical). CVE-2022-3900.

Marcin MotwickiMarcin Motwicki
Read
Anatomy of a Breach: A Ransomware Attack on the Polish Healthcare Sector
Breach Analyses
18 min read·March 8, 2026

Anatomy of a Breach: A Ransomware Attack on the Polish Healthcare Sector

A detailed analysis of a real ransomware incident that paralyzed a hospital network. From the initial access vector to full remediation — step by step.

Marcin MotwickiMarcin Motwicki
Read
How to Secure an API Against Attacks? A Practical Guide
Defense Guides
12 min read·February 15, 2026

How to Secure an API Against Attacks? A Practical Guide

In the age of microservices, the API is the backbone of modern software. Learn the key practices for protecting programming interfaces against attacks.

Marcin MotwickiMarcin Motwicki
Read
NIS2 in Practice: What You Must Implement by October 2026
Regulations & Compliance
10 min read·January 5, 2026

NIS2 in Practice: What You Must Implement by October 2026

The NIS2 Directive places new obligations on operators of essential services. See which requirements you must meet and how to prepare for them.

Marcin MotwickiMarcin Motwicki
Read