BuffaloWill
4 exploits
Active since Jan 2020
Serpico 1.3.0 - Stored Cross-Site Scripting via admin/list_user auth_type Parameter
CVSS 4.8
Serpico 1.3.0 - Stored Cross-Site Scripting via User Type Parameter
CVSS 4.8
Serpico 1.3.0 - Stored Cross-Site Scripting via Author Parameter
CVSS 4.8
Serpico < 1.3.3 - Authenticated Exposure of Resource to Wrong Sphere via Admin Attachments Backup Endpoint
CVSS 6.5