Alexander Todorov
10 exploits
Active since Nov 2022
Kiwi TCMS < 12.2 - OS Command Injection via Untrusted github.head_ref Field
CVSS 8.8
Kiwi TCMS < 12.4 - Stored Cross-Site Scripting via File Upload Bypass
CVSS 8.1
Kiwi TCMS < 12.5 - Unrestricted Upload of File with Dangerous Type via Nginx Configuration
CVSS 8.1
kiwi_tcms < 11.6 - Stored Cross-Site Scripting in Test Plan
CVSS 5.4
Kiwi TCMS < 11.7 - Weak Password Requirements
CVSS 6.5
Kiwi TCMS < 12.0 - Unauthenticated Brute-Force Attack via Login Page
CVSS 7.5
Kiwi TCMS < 12.0 - Denial of Service via Password Reset Email Spam
CVSS 7.5
Kiwi TCMS < 12.1 - Stored Cross-Site Scripting via SVG File Upload
CVSS 7.6
Kiwi TCMS < 12.2 - OS Command Injection via Untrusted github.head_ref Field
CVSS 8.8
Kiwi TCMS < 12.5 - Unrestricted Upload of File with Dangerous Type via Nginx Configuration
CVSS 8.1