Alexandre ZANNI
19 exploits
Active since Aug 2018
Kirby <3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, 3.9.6 - XXE
CVSS 6.8
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3
Umbraco CMS <7.15.10 - Authenticated RCE
CVSS 7.2
REDCap 8.0-8.10.2 - Stored Cross-Site Scripting in Admin Panel and Survey System
CVSS 4.8
Alfresco < 5.2.7 and < 6.2.0 - Cross-Site Scripting via File URL Property
CVSS 5.4
Alfresco < 5.2.7 and < 6.2.0 - Stored Cross-Site Scripting via User Profile Photo SVG
CVSS 5.4
PPress 0.0.9 - Privilege Escalation
CVSS 8.0
REDCap 8.0-8.10.2 - Stored Cross-Site Scripting in Admin Panel and Survey System
CVSS 4.8
OpenEMR < 5.0.1.4 - Authenticated Arbitrary PHP File Upload via Site Files Manager
CVSS 8.8
OpenEMR 5.0.1 - Remote Code Execution (Authenticated) (2)
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2)
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3
FUEL CMS < 1.4.2 - Unauthenticated Remote Code Execution via Pages Filter or Preview Data Parameter
CVSS 9.8
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
CMSuno 1.6.2 - Authenticated Remote Code Execution via Username Parameter
CVSS 8.8
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass via X-Forwarded-For Header
CVSS 9.8
Alfresco < 5.2.7 and < 6.2.0 - Authenticated Stored Cross-Site Scripting via Uploaded Document
CVSS 5.4
Netmake ScriptCase <9.12.006 - Command Injection
CVSS 6.7
Umbraco CMS 7.12.4 - Remote Code Execution (Authenticated)