Think Love Share208IN STACK · 2026-02-07 00:00
Enketo 6.2.1 - Auth-Bypass, SSRF, and XXE Browser Abuse to File Read
Introduction This training session was focused on white-box code review, application, and system runtime introspection. We wanted to work on a JavaScript backend framework and Enketo Express seemed to be a good candidate. The source code is available on GitHub - enketo/enketo-express and the version we assessed was the version 6.2.1, built with the official Dockerfiles. Enketo is a cross platform software used to (quoting): Deploy and conduct surveys that work without a connection, on any dev...