The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/MadnetM/cloud-active-defense-replica
- https://github.com/SAP/cloud-active-defense
- https://github.com/tanjiti/sec_profile