NiceHash Miner Excavator 1.6.7c Cross Site Request Forgery
Posted by deepcore on May 19, 2021 – 6:02 pm
NiceHash Miner Excavator versions 1.6.7c and below suffer from a cross site request forgery vulnerability. The issue enables any external web site to send commands to the local miner instance, and to redirect the mined coins to an arbitrary mining address.
Post a reply
You must be logged in to post a comment.