Alex Strick van Linschoten
4 exploits
Active since Jun 2024
zenml < 0.56.2 - Authenticated Missing Authorization via API PUT /api/v1/users/id Endpoint
CVSS 6.5
zenml <= 0.55.5 - Clickjacking via Missing X-Frame-Options Header
CVSS 6.1
zenml < 0.57.0rc2 - Account Takeover via Unlimited Password Change Attempts
CVSS 5.4
zenml 0.57.1 - Reflected Cross-Site Scripting via Survey Redirect Parameter
CVSS 6.1