This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
HD Moore
hdm.io
did:plc:rzrcljpec5e52wvcacwxds4w
Next.js dropped a CVSS 9.1 authentication bypass vulnerability (CVE-2025-29927) over the weekend. This flaw is trivially exploitable by sending the header `x-middleware-subrequest: true`. Over 300k hits in Shodan, find more at:
https://www.runzero.com/blog/next-js/
2025-03-23T02:42:57.420Z