Chaining file upload bypass and stored XSS to create admin accounts

Two medium-severity findings. No critical vulnerabilities anywhere in the report. And we created an admin account in the client’s application without anyone noticing. That’s the problem with scoring vulnerabilities in isolation. The target We were brought in to test a SaaS platform used by businesses for internal operations. Standard web app pen test, authenticated testing across multiple user roles, looking at the usual suspects: access controls, input validation, session management, business logic. ...

March 28, 2026 · 9 min · 1892 words · Kurtis Baron

Fixing the Burp Suite clipboard crash on Hyprland

If you run Burp Suite on Hyprland, you might know this one already. Copy a request from Repeater, switch to Chromium to paste it into your notes, and Chrome just dies. No warning. No error dialog. Just gone. You end up running pkill -9 chromium, reopening it, restoring your tabs, and getting back to work. Then you copy from Burp again and it happens again. I put up with this for about three months before I sat down and actually fixed it. ...

March 22, 2026 · 4 min · 806 words · Kurtis Baron