Lauri Ojansivu
32 exploits
Active since May 2023
Wekan < 6.84 - Authenticated Stored Cross-Site Scripting via Reaction to Comment Feature
CVSS 5.4
Wekan < 8.21 - Improper Authorization via setBoardOrgs Function
CVSS 5.0
Wekan < 8.21 - Improper Authorization via REST API Checklist Items Manipulation
CVSS 6.3
WeKan <8.20 - Improper Access Controls
CVSS 6.3
WeKan <8.20 - Improper Access Controls
CVSS 6.3
WeKan < 8.21 - Missing Authorization in Position-History Tracking
CVSS 4.3
Wekan < 8.21 - Improper Access Control in LDAP User Sync
CVSS 6.3
Wekan < 8.21 - Improper Access Controls in Attachment Migration
CVSS 6.3
WeKan < 8.21 - Improper Access Control in Attachment Storage
CVSS 6.3
Wekan < 8.21 - Improper Access Control in REST Endpoint
CVSS 4.3
Wekan < 8.21 - Information Disclosure in Meteor Publication Handler
CVSS 4.3
Wekan < 8.21 - Improper Access Control in Administrative Repair Handler
CVSS 6.3
Wekan < 8.21 - Information Disclosure in Activity Publication Handler
CVSS 5.3
Wekan < 8.21 - Missing Authorization in Rules Handler
CVSS 4.3
Wekan < 8.19 - Incorrect Privilege Assignment in Custom Translation Handler
CVSS 6.3
WeKan < 8.35 Missing Authorization via Integration REST API
CVSS 8.3
WeKan < 8.35 SSRF via Webhook URL
CVSS 8.5
Wekan 8.32-8.33 - Authenticated Insecure Direct Object Reference in Custom Fields Endpoint
CVSS 6.5
Wekan 8.32-8.33 - Authenticated Server-Side Request Forgery via Attachment URL Loading
CVSS 8.1
Wekan 8.31.0-8.33 - Info Disclosure
CVSS 8.2
Wekan 8.31.0-8.33 - Info Disclosure
CVSS 7.5
Wekan 8.31.0-8.33 - Info Disclosure
CVSS 6.5
WeKan < 8.19 - LDAP Injection in Authentication Filter
CVSS 9.8
WeKan < 8.19 - Incorrect Authorization in Attachment Upload API
CVSS 7.5
WeKan < 8.19 - Unauthorized Attachment Metadata Exposure via Attachments Publication
CVSS 4.3