Irina Belyaeva

2 exploits Active since Jan 2021
CVE-2021-3131 NOMISEC HIGH WRITEUP
1C < 8.3.17.1851 - Weak Encryption
The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.
1 stars
CVSS 7.5
CVE-2021-3395 NOMISEC MEDIUM WRITEUP
Pryaniki - XSS
A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.
1 stars
CVSS 5.4