Jan Henning Thorsen

2 exploits Active since Jun 2020
CVE-2020-14423 WRITEUP MEDIUM WRITEUP
Convos <4.20 - Info Disclosure
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.
CVSS 5.3
CVE-2021-42584 WRITEUP MEDIUM WRITEUP
Convos < 6.32 - XSS
A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.
CVSS 5.4