Tech News
← Home  ·  All topics

Rest Api

3 GoKawiil briefs on this topic

Elementor plugin CSRF bug let attackers create WordPress admin accounts

Patchstack disclosed a cross-site request forgery flaw in the Elementor Website Builder plugin, affecting versions 4.3.0 and 4.3.1, used on up to 2 million WordPress sites. The bug let attackers trick a logged-in administrator into clicking a malicious link that silently created a new admin account under attacker control. Elementor patched the issue in version 4.3.2, released two days after Patchstack's report.

Show HN: GET Together lets users post to a social feed via plain GET requests

A hobby project called GET Together implements an entire social network—posting, replying, hearting and deleting—using only HTTP GET requests instead of POST. Posts are created by hitting URLs like /post?name=alice&text=hello, with an optional session cookie enabling later deletion, and a /feed endpoint returning JSON. The system includes basic profanity and crypto-content moderation, plus a reporting mechanism for abuse review.

Qisutu 1.0.2 open-source ticketing system reaches stable release

Qisutu, a self-hosted, open-source help desk and ticketing platform built with Perl/CGI, MariaDB/MySQL and Template Toolkit, has reached version 1.0.2, marking its first stable, production-ready release. The software includes an agent and customer portal, email handling, directory login, automation, a knowledge base, CMDB, reporting and a REST API, and ships with eleven complete interface languages including English, German, French and Spanish. Installation is done via a shell script that sets up a dedicated system user and lets administrators pick their interface language during setup.