7 min read
How an Outdated Next.js and React Got the Sensii Landing Page Hacked
The Sensii landing page ran a Next.js and React version with a critical remote-code-execution bug. Here's how attackers exploited it, what their code did, what visitors saw, and how we fixed it.
securityincidentnext.jsreactreact2shellclickfix