Berat Aksit

2 exploits Active since Sep 2025
CVE-2025-57292 WRITEUP MEDIUM WRITEUP
Todoist - XSS
Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.
CVSS 6.1
CVE-2025-57292 WRITEUP MEDIUM WRITEUP
Todoist - XSS
Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.
CVSS 6.1