Bastion Security

Advisories

Stay ahead of emerging threats with real-time advisories, research and updates from our security team.
Talk to an expert
1 Jan 2025
Silverstripe - Cross-Site Scripting (XSS) Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in the administrator panel of Silverstripe CMS, specifically in the handling of the user input within the form messages module.
Advisories

Uncovering threats before they hit the headlines

Our security advisories are more than alerts — they’re the result of deep technical analysis, forensic investigation, and real-world testing by our specialists.
January 22, 2025
Silverstripe - Cross-Site Scripting (XSS) Vulnerability
A Cross-Site Scripting (XSS) vulnerability has been identified in the administrator panel of Silverstripe CMS, specifically in the handling of the user input within the form messages module.
January 21, 2025
Silverstripe - Host Header Injection
A Host header injection vulnerability in Silverstripe has been identified that allows an attacker to poison the password rese
November 25, 2024
Statamic CMS
Sam Schroder found a local file inclusion (write only) vulnerability inside of the upload functionality of Statamic CMS. This affects front end components like forms with `assets` fields.
October 10, 2024
Microsoft - Authenticated Account Takeover
A valid Microsoft session can be abused to reset the users password and remove multi-factor authentication (MFA) in order to takeover an account.
July 24, 2024
Silverstripe - Cross Site Scripting (XSS) vulnerabiltiy
June 21, 2024
Passwordstate - Authentication Bypass Vulnerability
Roy Sugiyama found an authentication bypass vulnerability that could be used to take over any Passwordstate user account with just the knowledge of the victim's username.
May 30, 2024
FarCry Core Framework - Multiple issues
Multiple vulnerabilities were discovered in the FarCry Core framework which could allow an unauthenticated user to arbitrarily upload files and perform remote code execution on the underlying server.
November 13, 2023
Security Feature Bypass In Zitadel
Jack Moran discovered a security feature bypass via a race condition within the Zitadel "password lockout policy" feature.
November 7, 2023
Zitadel one click silent account takeover
Ethan Mckee-Harris discovered stored cross-site scripting and email injection which could lead to silent account takeover.
July 12, 2023
Security Feature Bypass In ASP.NET and Visual Studio
Jack Moran, TC, and Ethan McKee-Harris discovered a security feature bypass within the SignInManger in ASP.NET.
May 31, 2023
Kramer VIA GO²
Jim Rush and Tomais Williamson discovered multiple issues within the Kramer VIA GO² devices, resulting in unauthenticated Remote Code Execution (RCE). Other Kramer devices may be affected.
January 31, 2023
perfSONAR — Multiple issues
Daniel Nemeth found a Server-Side Request Forgery vulnerability via the *host* header that could be used to scan the internal network. Moreover, an arbitrary file read vulnerability was identified, which could allow an attacker to grep for any string
November 16, 2022
Spectrum Spatial Analyst 20.1 — Multiple issues
Jack Moran discovered a Server-Side Request Forgery vulnerability and a Path Traversal sequence that leads to an authentication bypass in Precisely Spectrum Spatial Analyst version 2020.1.0 S44. Spectrum Spatial Analyst is an interactive mapping and
August 8, 2022
Genero Enterprise — Multiple issues
Matthew Dekker and Michael Tsai found multiple issues across the Genero Enterprise by Four JS suite of applications. The issues allowed for various impacts on products, including remote code execution (RCE) in any Android application built using Gene
July 6, 2022
Wiris MathType — Path traversal vulnerability
Justina Koh and Jim Rush discovered a path-traversal vulnerability in the MathType library created by Wiris. MathType is a multi-language library used as an equation editor for creating mathematical expressions. It is currently available as a Moodle
November 1, 2021
Accellion kiteworks — Privilege escalation vulnerability
Tomais Williamson found an authenticated privilege escalation vulnerability in the Accellion kiteworks web application. A malicious website administrator could use this to gain shell access to the application with root privileges.
May 27, 2021
Ruby Dragonfly — Argument Injection vulnerability
Michael Tsai
March 19, 2021
Silverstripe — Cross Site Scripting (XSS) vulnerability
Michael Tsai found a Cross Site Scripting vulnerability in the Silverstripe CMS symbiote/silverstripe-queuedjobs module. This vulnerability allows an attacker to inject an arbitrary payload in the CreateQueuedJobTask dev task via a specially crafted
April 21, 2020
Cisco CWS — SQL Injection vulnerability
Jason Xie found an authenticated SQL injection vulnerability in the Cisco Cloud Web Security (CWS) web application. If exploited an attacker could extract or modify values stored in the underlying database.
April 21, 2020
VMWare vCloud API — Access Control vulnerability
Jason Xie found that if you have a local organisation administrator credentials, by using the API you can create, remove or revert snapshots of vApps and VMs located in another organisation’s VDC.
March 30, 2020
TelStrat Engage — Multiple issues
David Robinson found multiple issues in TelStrat Engage, a product used for recording phone calls, typically for training and customer experience purposes.
March 30, 2020
RSA Archer — Multiple issues
Ahmad Ashraff Ahmad found multiple issues in RSA Archer Suite by RSA Security.
December 17, 2019
SolarWinds SERV-U — CSRF vulnerability
Claudio Contin found that CSRF tokens are not implemented in the file upload functionality of the Secure File Transfer web client.
December 9, 2019
Squiz Matrix CMS — Multiple issues
Stephen Shkardoon identified multiple issues in the Squiz Matrix CMS product, which could lead to a remote code execution vulnerability.
March 6, 2019
ASP.NET Boilerplate — Input Validation vulnerability
Claudio Contin found an input validation issue with ABP 4.2.
February 20, 2019
Teracue ENC-400 — Multiple issues
Stephen Shkardoon found multiple issues in the Teracue ENC-400 hardware, including a pre-authentication remote code execution vulnerability.
March 1, 2018
WatchGuard Access Points — Multiple issues
Stephen Shkardoon recently found multiple issues in WatchGuard Access Points which result in remote code execution.
Testimonials

Our customers

Look what our customers have to say
Service Development Manager
Government Agency
"Great service, clear, detailed and precise information on what our vulnerabilities were and what needs addressing. Couldn't have been easier to deal with and very professional."
Business Manager
Charity
"As a small charity that was the beneficiary of the Hacking for Heroes programme it has been fantastic working with the team at Bastion. The engagement definitely exceeded my expectations and I cannot recommend the Bastion team highly enough."
Chief Information Officer
Government Agency
"As ever, a professional, effective and efficient engagement with Bastion that has left us feeling more secure. Thanks team!"
Manager
Research Organisation
"Genuinely impressed and thankful for the incredibly short turn around time and detailed nature of the report and audit services provided."
What comes next

We have the tools to pinpoint risks

Whether it’s hidden vulnerabilities or patterns you might miss, we help you stay one step ahead and make confident, informed decisions. Understand how our services can help your business uncover critical risks

Talk to an expert
Employee Cyber Training & Awareness
Your people are your first line of defence. Our cyber training builds awareness, sharpens instincts and turns everyday staff into assets.
Advisory
When clarity is critical and stakes are high, our advisory services deliver strategic, executive-level security expertise that empowers decision-making