Alexandre Alapetite
11 exploits
Active since Mar 2023
FreshRSS 57e1a37-00f2f04 - Auth Bypass
FreshRSS 1.9.0-1.21.0 - Sensitive Information Disclosure in Greader API Logs
CVSS 4.0
FreshRSS < 1.26.2 - Information Disclosure via Directory Existence Check
CVSS 7.5
FreshRSS < 1.26.2 - Stored Cross-Site Scripting via SVG Favicon in Feed
CVSS 6.7
FreshRSS < 1.26.2 - Cross-Site Scripting via Iframe Srcdoc Attribute
CVSS 6.7
FreshRSS < 1.26.2 - Favicon Cache Poisoning via Proxy Manipulation
CVSS 4.3
FreshRSS < 1.26.2 - Authenticated Server-Side Request Forgery via Add Feed Functionality
CVSS 7.1
FreshRSS < 1.26.2 - Authenticated Remote Code Execution via Update URL Manipulation
CVSS 7.2
FreshRSS 1.23.0-1.27.0 - Unauthenticated Path Traversal via Language Parameter
CVSS 8.8
FreshRSS 1.27.0-1.28.0 - Denial of Service via Proxy Retry-After Header Manipulation
CVSS 4.3
FreshRSS < 1.28.0 - Account Takeover via Weak PRNG Session Tokens
CVSS 9.8