diff --git a/src/content/changelog/waf/2025-07-14-waf-release.mdx b/src/content/changelog/waf/2025-07-14-waf-release.mdx index 2197fb5a4dd733..27ee5690579c07 100644 --- a/src/content/changelog/waf/2025-07-14-waf-release.mdx +++ b/src/content/changelog/waf/2025-07-14-waf-release.mdx @@ -12,7 +12,7 @@ This week’s vulnerability analysis highlights emerging web application threats - XSS – Attribute Overloading: A novel cross-site scripting technique where attackers abuse custom or non-standard HTML attributes to smuggle payloads into the DOM. These payloads evade traditional sanitization logic, especially in frameworks that loosely validate attributes or trust unknown tokens. - XSS – onToggle Event Abuse: Exploits the lesser-used onToggle event (triggered by elements like `
`) to execute arbitrary JavaScript when users interact with UI elements. This vector is often overlooked by static analyzers and can be embedded in seemingly benign components. -- SQLi – Obfuscated Boolean Logic: An advanced SQL injection variant that uses non-standard Boolean expressions, comment-based obfuscation, or alternate encodings (for example, `/*!true*/`, `AND/**/1=1`) to bypass basic input validation and WAF signatures. This technique is particularly dangerous in dynamic query construction contexts. + **Impact** @@ -53,16 +53,5 @@ These vulnerabilities target both user-facing components and back-end databases, Block This is a New Detection - - Cloudflare Managed Ruleset - - - - 100800 - SQLi - Obfuscated Boolean - Log - Block - This is a New Detection - diff --git a/src/content/changelog/waf/2025-07-28-waf-release.mdx b/src/content/changelog/waf/2025-07-28-waf-release.mdx index 6046cd432849a7..3374f46caf0c04 100644 --- a/src/content/changelog/waf/2025-07-28-waf-release.mdx +++ b/src/content/changelog/waf/2025-07-28-waf-release.mdx @@ -89,16 +89,5 @@ These vulnerabilities target user-facing components, web application servers, an Block This is a New Detection - - Cloudflare Managed Ruleset - - - - 100822 - WordPress:Plugin:WPBookit - Remote Code Execution - CVE:CVE-2025-6058 - Log - Block - This is a New Detection - \ No newline at end of file