Daniel Vaz Gaspar
9 exploits
Active since Jun 2021
Flask-AppBuilder <= 3.2.3 - Unauthenticated User Enumeration via Timing Attack
CVSS 5.3
Flask-AppBuilder <3.2.2 - Open Redirect
CVSS 7.2
Flask-AppBuilder <3.3.4 - Auth Bypass
CVSS 8.1
Flask-AppBuilder <4.3.2 - Info Disclosure
CVSS 2.7
Flask-AppBuilder <4.3.11 - OpenID Authentication Bypass via Forged Provider Request
CVSS 9.1
Flask-AppBuilder 4.1.4-4.2.1 - Cross-Site Scripting on OAuth Login Page
CVSS 4.3
Flask-AppBuilder <4.5.1 - Info Disclosure
CVSS 3.6
Flask-AppBuilder < 4.6.2 - Unauthenticated Open Redirect via Host Header Manipulation
CVSS 4.3
Flask-AppBuilder < 4.8.1 - Improper Authentication via Password Reset Endpoint
CVSS 6.5