Rhino Security Labs

Strategic & Technical Blog

Referral Beware, Your Rewards are Mine (Part 1)

Whit Taylor
August 27, 2025

Referral rewards programs are nearly ubiquitous today, from consumer tech to SaaS companies, but are rarely given much security oversight. In this blog post we’ll dig into the common technical implementations of rewards programs on…

Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities  

CVE-2025-26147: Authenticated RCE In Denodo Scheduler 

CVE-2024-55963: Unauthenticated RCE in Default-Install of Appsmith

Whit Taylor

While reviewing the Appsmith Enterprise platform, Rhino Security Labs uncovered a series of critical vulnerabilities affecting default installations of the product. Most severe among them is CVE-2024-55963, which allows unauthenticated…