Bernhard Rusch
24 exploits
Active since Apr 2019
pimcore < 5.7.1 - Authenticated Remote Code Execution via Unserialize in Bulk-Commit Endpoint
CVSS 8.8
pimcore <6.8.8 - Local File Inclusion
CVSS 7.1
pimcore < 5.7.1 - Authenticated Remote Code Execution via PHAR Deserialization
CVSS 8.8
pimcore < 5.7.1 - Authenticated Unrestricted File Upload via Long Filename Bypass
CVSS 8.8
pimcore < 6.3.0 - Stored Cross-Site Scripting in Translations Grid
CVSS 6.1
pimcore < 6.2.2 - Inappropriate Encoding for Output Context
CVSS 9.8
Pimcore < 6.3.0 - Cross-Site Scripting in Email Log Preview Window
CVSS 6.1
pimcore < 6.2.2 - Unauthenticated Excessive Authentication Attempts
CVSS 9.8
pimcore < 6.2.2 - Username Enumeration via Forgot Password Distinct Error Messages
CVSS 7.5
pimcore < 10.2.6 - Business Logic Errors
CVSS 4.3
pimcore < 10.2.8 and 10.2.9 - Cross-Site Scripting
CVSS 5.4
pimcore < 10.2.8 and >=0 < 10.2.9 - Cross-Site Scripting
CVSS 5.4
pimcore < 10.2.8 and 10.2.9 - SQL Injection
CVSS 8.8
pimcore < 10.2.7 - Stored Cross-Site Scripting
CVSS 5.4
Packagist pimcore/pimcore <10.2.7 - XSS
CVSS 6.1
Packagist pimcore/pimcore <10.2.7 - File Injection
CVSS 7.8
GitHub pimcore/pimcore <10.4.0 - XSS
CVSS 5.4
GitHub pimcore/pimcore <10.4.0 - XSS
CVSS 5.4
pimcore < 10.3.0 and 10.4.0 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.3.0 and 10.3.0-10.4.0 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.3.0 and 10.3.0-10.4.0 - Stored Cross-Site Scripting
CVSS 5.4
pimcore < 10.4.4 - SQL Injection via Listing Class Order/Group Methods
CVSS 7.5
pimcore < 10.5.19 - SQL Injection
CVSS 8.8
Pimcore Admin Classic Bundle < 1.2.3 - Account Takeover via Host Header Injection in Password Reset
CVSS 8.8